{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2556a2a6-3ec2-5fb7-9476-991565975178",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/platform-browser",
      "purl": "pkg:npm/%40angular/platform-browser@19.2.21-tuxcare.9",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/platform-browser@19.2.21-tuxcare.9",
      "version": "19.2.21-tuxcare.9",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@19.2.21-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:bef74123-2d99-5b22-a574-4a5325772a69",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 19.2.21-tuxcare.9 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@19.2.21-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:06a7b11d-45e3-5daa-8b52-8a485e2ff647",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 19.2.21-tuxcare.9 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@19.2.21-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:94b9e73a-602e-52a2-b29b-5d6bf9ba6ca2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-27970 does not affect version 19.2.21-tuxcare.9 of @angular/platform-browser. already_fixed \u2014 The target repository (Angular 19.2.21-tuxcare.4) already contains the fix for CVE-2026-27970. The vulnerability (XSS via unsanitized HTML attributes in ICU message translations) has been addressed by TuxCare in prior backports. The defense mechanism in packages/core/src/render3/i18n/i18n_parse.ts lines 829-843 implements the same attribute allowlist validation as the vendor patch, blocking URI...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@19.2.21-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:8492fef3-e6ad-547a-95be-29dc5ce5c7c4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 19.2.21-tuxcare.9 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@19.2.21-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:ecda87a3-ade0-5e69-bd6c-6b068091f0cb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 19.2.21-tuxcare.9 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@19.2.21-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:3238a050-a7da-5805-8113-378effe80d57",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 19.2.21-tuxcare.9 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@19.2.21-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:09e53ebe-f23f-575f-a620-19198ab3a194",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 19.2.21-tuxcare.9 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@19.2.21-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:378b9724-bce5-5928-a541-8d007f6854a4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 19.2.21-tuxcare.9 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@19.2.21-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:e6c5e391-c846-5123-bd60-45927f5198a7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 19.2.21-tuxcare.9 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@19.2.21-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:1b5fcc8c-fa1e-5d4d-91ef-d7ddd61ef3c8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 19.2.21-tuxcare.9 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@19.2.21-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:ff3f926c-66ef-5752-93ed-40110d5e4638",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 19.2.21-tuxcare.9 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@19.2.21-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:4737af1c-a5c6-5293-8b25-fe3ac8a60bc7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 19.2.21-tuxcare.9 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@19.2.21-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:7db62493-394f-5642-83a1-222af32e4f6a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 19.2.21-tuxcare.9 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@19.2.21-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:80b983ee-3c90-5160-b0c3-441f863e9996",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 19.2.21-tuxcare.9 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@19.2.21-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:c13ae061-23c5-5718-8c76-598f1d04a7fe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 19.2.21-tuxcare.9 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@19.2.21-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:1d032bb1-3cd4-5b1c-a8e0-ace176744377",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 19.2.21-tuxcare.9 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@19.2.21-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:c42617f8-e119-5c52-a19b-c6eebe5f9be5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 19.2.21-tuxcare.9 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@19.2.21-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:99b889d3-be17-587a-b0a6-65a7a6742688",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 19.2.21-tuxcare.9 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@19.2.21-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:16d0c0ff-30f8-5bb0-b6a0-86c5b4c7d318",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 19.2.21-tuxcare.9 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@19.2.21-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:0a191b09-c498-5d1d-8763-6d86c7af0a01",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 19.2.21-tuxcare.9 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@19.2.21-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:081c5def-7941-5f26-9262-2c5d2bb6d4d9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 19.2.21-tuxcare.9 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@19.2.21-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:cc936f49-6808-5d57-a9b5-f38dffe4c111",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 19.2.21-tuxcare.9 of @angular/platform-browser. not_affected \u2014 CVE-2026-88056 does not affect this Angular v19.2.21-tuxcare.5 target. The CVE describes a vulnerability where `String.prototype.trim()` strips Unicode whitespace (U+00A0, U+FEFF) from URLs during SSR, converting same-origin relative paths into cross-origin protocol-relative URLs that leak credentials. The v19.2.x branch uses a simpler URL resolution implementation created by TuxCare (commit 81...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@19.2.21-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:8be71218-a94f-5a39-a98c-93525910a369",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 19.2.21-tuxcare.9 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@19.2.21-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:498b1c60-068f-5590-ad0a-f3a79c64cf76",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 19.2.21-tuxcare.9 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@19.2.21-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:0b396313-d6d5-5676-82a2-5a79b38e8bda",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 19.2.21-tuxcare.9 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@19.2.21-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:1d7620d3-4f86-597e-9e17-37c754ede94a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 19.2.21-tuxcare.9 of @angular/platform-browser."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-browser@19.2.21-tuxcare.9"
    }
  ]
}