{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:db9fd087-eb4e-5127-bffb-0116740907bd",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/platform-browser",
      "purl": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7",
      "version": "17.1.0-tuxcare.7",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:e94b0af5-8ab4-5d14-91fd-e37cfd2b3aa2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.1.0-tuxcare.7 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:27581e11-d558-57f6-a98b-32b248952578",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.1.0-tuxcare.7 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:454b6946-aadb-5c03-9762-e63d72663ef8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.1.0-tuxcare.7 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:4ea7a457-a1b8-5019-988e-187241631d64",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 17.1.0-tuxcare.7 of @angular/platform-browser, and is fixed in 17.1.0-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:4ea9da10-b75f-503f-b0ec-d4f56eca13dd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 17.1.0-tuxcare.7 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:22bf8a82-e312-5592-87a1-ba3c6c75c5d4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.1.0-tuxcare.7 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:c7249cf2-7683-5341-bd57-908012736b51",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.1.0-tuxcare.7 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:cc9dfe78-df58-5649-b96e-831fd5492dfa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.1.0-tuxcare.7 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:7318aca3-4222-597b-a131-db91440d5a36",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 17.1.0-tuxcare.7 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:8b805be7-b26d-502c-9af9-822cba2f2b75",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.1.0-tuxcare.7 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:bac6abd4-407a-55a1-81f3-97e27368ec0a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.1.0-tuxcare.7 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:3d288821-bb4e-55a9-a687-332446a58e4a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.1.0-tuxcare.7 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:3d971e39-4494-5600-978a-2336003efff9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.1.0-tuxcare.7 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:a2563ca5-e3b9-5b73-a313-f487c7ec3f9c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.1.0-tuxcare.7 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:268e4f00-5d9f-501b-a744-362a121e92c4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.1.0-tuxcare.7 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:881d245f-b33c-5429-b774-20b4539d95a7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.1.0-tuxcare.7 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:b62029ce-8f2e-5aa0-9f3f-226e95302b4f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.1.0-tuxcare.7 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:9c5d9b7d-a860-5285-a0cc-f600dba43ff5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.1.0-tuxcare.7 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:c1d8f06b-dab2-5781-b110-cfc4c841171f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.1.0-tuxcare.7 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:59d01e4c-0cd6-5a23-8fe6-4a0c355b20d5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.1.0-tuxcare.7 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:bf0a2820-2bb4-5996-9a8e-32244de4d89a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 17.1.0-tuxcare.7 of @angular/platform-browser. not_affected \u2014 Angular v17.1.0 does not have the TwoWayProperty IR operation that is the subject of CVE-2026-54265. Two-way bindings are desugared into separate property and event bindings before template pipeline processing, with the property half using the same parsePropertyBinding() code path as one-way property bindings, which are properly sanitized.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:bbcddb36-14d1-5d5a-93cb-6176f642606d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.1.0-tuxcare.7 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:0967de99-cf2e-58f4-a46d-f9e1ab9035ab",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.1.0-tuxcare.7 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:2c9cefb1-bf9a-5765-a67a-d385508b5ad8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.1.0-tuxcare.7 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:b141a365-465a-5169-aa25-94ce377a6340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 17.1.0-tuxcare.7 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:f68ebab8-4013-5dac-b41d-9c05a8f0dd60",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 17.1.0-tuxcare.7 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:530ea408-5496-55ed-9674-38efd5d28b8a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 17.1.0-tuxcare.7 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:e5af8503-804d-52ac-a244-1bf8e12447d8",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.1.0-tuxcare.7 of @angular/platform-browser. not_affected \u2014 Angular 17.1.0 was never vulnerable to CVE-2026-88056. The vulnerability exists only in newer Angular versions (v18+, v19+, v20+ before fixes) where a url.ts file with a parseUrl function that uses String.prototype.trim() was introduced. Angular 17.1.0 does not have this file in the upstream release. TuxCare created url.ts for their 17.1.0 fork (commit e06d36f339 by ejarocki@cloudlinux.com) but...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:4cd967ac-7e59-5e54-8730-b4fdb21a0409",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 17.1.0-tuxcare.7 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:db70f391-c8bc-5ee8-bfb6-5544b0637918",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88058 does not affect version 17.1.0-tuxcare.7 of @angular/platform-browser. not_affected \u2014 The Angular repository (version 17.1.0-tuxcare.5 at SHA 1b802ce320) is not affected by CVE-2026-88058 because it does not contain the vulnerable source code. The vulnerability exists in the domino library's HTML serialization code (lib/NodeUtils.js), which Angular references as a dependency in package.json but does not vendor. The upstream patch (89b20568dfaee1ec8e0b3bcf1872acdddd2f4fef) is a D...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:e256335f-d299-5d21-86d8-e1c3f357dbff",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 17.1.0-tuxcare.7 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:dc2dc615-7546-5b6b-ae2d-eb2ac4114833",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 17.1.0-tuxcare.7 of @angular/platform-browser."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-browser@17.1.0-tuxcare.7"
    }
  ]
}