{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:582d0bfa-c1c8-5949-a862-29f2b95cc819",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/platform-browser",
      "purl": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5",
      "version": "16.2.11-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9be7c89c-b211-5667-820c-2cc0881e6bce",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 16.2.11-tuxcare.5 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2aab07b3-c89a-573f-91f2-d59941a78e71",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.11-tuxcare.5 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5e47e957-6c57-5309-8ed7-764a7fb64233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 16.2.11-tuxcare.5 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:cbb90aab-c01e-5fd1-95ea-5b190c34beed",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 16.2.11-tuxcare.5 of @angular/platform-browser, and is fixed in 16.2.11-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f2a7d7e6-058d-55f2-a0df-7582d45ac01f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 16.2.11-tuxcare.5 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:57a6bdf1-45eb-5ae6-af18-7556b4e36caa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 16.2.11-tuxcare.5 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1a784ae2-871e-5708-802d-764c1d4e58d0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 16.2.11-tuxcare.5 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:47464d67-c4e0-5b1c-8003-7d3ae36d6fce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 16.2.11-tuxcare.5 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:27d1f7fe-a46c-56e9-8386-1005779111a4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 16.2.11-tuxcare.5 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:371458ab-7452-580f-a4d8-91fafa46a24e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 16.2.11-tuxcare.5 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:08dc6626-c45a-5b24-a1a1-7313a437f502",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 16.2.11-tuxcare.5 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:979993bf-c21a-572f-b288-8c0f0bbbfd60",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 16.2.11-tuxcare.5 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:44a2210b-d9d5-5556-9f56-f5966998177a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 16.2.11-tuxcare.5 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:988a2ff9-80af-5af6-a79d-a222bd2938ec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 16.2.11-tuxcare.5 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:dc900841-40cf-5892-90bc-17c7b1b36418",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 16.2.11-tuxcare.5 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d0366aca-69f1-54ed-94b0-d57cb61070a3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 16.2.11-tuxcare.5 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6acceb64-cd54-5418-a695-9f5cafd0ed5a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 16.2.11-tuxcare.5 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ba19be2d-35c3-56b1-abf4-e34b9abd0e30",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 16.2.11-tuxcare.5 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:db856d4e-bc93-58e3-9f71-0ad2b4c8b9ff",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 16.2.11-tuxcare.5 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2233e67e-be65-535f-84f4-435d3b3b93c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 16.2.11-tuxcare.5 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:31da69ba-6007-5a4b-90dc-0ea66dc35e4a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 16.2.11-tuxcare.5 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c66eab4e-bb17-5406-b700-88271cab057c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 16.2.11-tuxcare.5 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:92f659e8-58d2-501a-911d-a8a5ba78b973",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 16.2.11-tuxcare.5 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ee600328-ca1a-5ebb-acb0-fc5823026105",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 16.2.11-tuxcare.5 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:39186b7f-abf2-5b7c-9fbb-6de62a97344c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 16.2.11-tuxcare.5 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:bafcd156-91cb-57fa-a5cf-c16e06d3c33c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 16.2.11-tuxcare.5 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:045086e5-5063-51e5-b2c8-ce6c13169f4c",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.11-tuxcare.5 of @angular/platform-browser. not_affected \u2014 Angular 16.2.11-tuxcare.2 is NOT affected by CVE-2026-88056. The vulnerability requires WHATWG URL validation combined with String.prototype.trim() on URLs during SSR, creating a discrepancy that enables SSRF. While the target uses WHATWG URL parsing (backported in commit c03fbfd7cc for CVE-2026-50168), it does NOT call String.prototype.trim() on URLs. The attack chain is broken at the trim() s...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:98a3a942-9568-5625-8990-db21a7e261ed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 16.2.11-tuxcare.5 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:440e1d81-da25-54d8-acd6-b86ae3ce639e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 16.2.11-tuxcare.5 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:288bd21a-e828-593b-94f3-5b65321734f9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 16.2.11-tuxcare.5 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e3487de4-97cd-58de-bf6e-99bb39ccf1e7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 16.2.11-tuxcare.5 of @angular/platform-browser."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-browser@16.2.11-tuxcare.5"
    }
  ]
}