{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4109a71e-6355-599a-bffc-feaed91cd33a",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/platform-browser",
      "purl": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8",
      "version": "18.1.2-tuxcare.8",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:931feed8-cb47-5149-ba2f-63b41d19e7c7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 18.1.2-tuxcare.8 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:0fa010aa-4bf4-5196-99ea-4bb1d99abbe6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:9b232c80-98d4-5ff0-a1b5-3f51804ce969",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:82dda116-8bfe-52c2-81f5-4c82558834c3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:31e40816-2b6b-5dc8-95f5-f8bbcdbd218f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 18.1.2-tuxcare.8 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:1855cb44-f9ae-526e-b9b2-e8050fd8c2d6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:fab8b0e5-0cc5-57f8-b9ce-6958b5de714a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f5d62e70-2bde-58b7-b9ea-f830753ddc40",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:87ab520e-cdae-52b1-bfd3-1c795873a63b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:2fcb0c94-d3e4-5332-9512-9322eb62e474",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:cf61aad9-df7f-5f84-8422-8a038a3233a7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:a4001596-97ee-5dc0-9947-d57fd96fe346",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:7ae594a7-fad2-569c-9c9a-1653900dcce9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:c2c3475a-080c-538a-ae0d-112e4a971f52",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:4d5c14a4-452c-5ded-b0af-4b0a21ecef29",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:29dac71a-94fd-5129-bac3-cc589b8cedcf",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50555 does not affect version 18.1.2-tuxcare.8 of @angular/platform-browser. already_fixed \u2014 The target Angular 18.1.2 repository has already been patched for this vulnerability. TuxCare commit 32991dd728 'fix all CVEs' added a cumulative domino patch that fixes both the NOSCRIPT XSS vulnerability (CVE-2026-50556, corresponding to the provided patch f74cccd) and the astral Unicode index bug (CVE-2026-50555). The patch is applied automatically to the domino dependency via patch-package ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:bde88556-d65f-5d38-9cd1-68ef26fe1ae1",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50556 does not affect version 18.1.2-tuxcare.8 of @angular/platform-browser. already_fixed \u2014 CVE-2026-50556 (XSS via noscript raw-text serialization in domino) has been fixed in this Angular repository. The fix is present in tools/esm-interop/patches/npm/domino+2.1.6.patch and is automatically applied to the domino dependency during installation via the postinstall script. The patch was added by TuxCare in commit 32991dd728 on 2026-07-01.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:5da93d0a-ac0e-5f7c-964b-506c6d1d740b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:4cf85a4b-796c-5e17-85de-cacce2d1bcb1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:c8ad2aea-4fd3-5bcc-8d51-dae5c864dfe9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:9bd7bb34-6fc5-5c12-8ffe-dd29968e8e0c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:da4216b0-653a-587d-bcad-66313a762fdc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:150c15b1-bada-505f-a36c-9ee9ad9f94b1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:025f6012-9498-51de-9f73-93be115cf210",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:fa44195b-2ab7-5d0a-902e-a93a3a37c2d0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:621d7516-a107-5d70-8df2-d1bf6cd327a3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:5ecaab89-7525-5b9a-b2c9-7bacd94e52f1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6003219d-2817-5aa2-a3c4-afdc00061abf",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.1.2-tuxcare.8 of @angular/platform-browser. not_affected \u2014 The target version (Angular 18.1.2) does NOT contain the vulnerable code pattern. CVE-2026-88056 describes a Unicode whitespace trimming vulnerability in Angular SSR's URL resolution, where `String.prototype.trim()` strips characters like U+00A0, converting same-origin paths into protocol-relative cross-origin URLs. The vulnerability was introduced in Angular v20.x during a refactoring (commit ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:e003427a-4c62-59be-8b6a-449b5032c9f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:d96ca590-00fa-55c0-ad9e-7959b5d1b45a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:4c8e89fa-37b3-5ce2-915e-9ed2eb185643",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:df3b56dc-7516-52a4-b5a7-7fb19a73c411",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-browser."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-browser@18.1.2-tuxcare.8"
    }
  ]
}