{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fa673e2b-125a-577a-ba70-ac19370a714e",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/platform-server",
      "purl": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7",
      "version": "18.1.2-tuxcare.7",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:c58082bb-2a9b-5153-8b09-9e333fbba996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 18.1.2-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:fb8a1bba-9d33-5e32-a13e-17dc70f4e7ab",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.1.2-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:cc63b8bc-849f-538d-8d2e-7fe570a49605",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.1.2-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:1a7cf408-645b-543b-99ca-234faf6f42ef",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 18.1.2-tuxcare.7 of @angular/platform-server, and is fixed in 18.1.2-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:3c3cf571-7bd0-559e-9076-c647358e6a48",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 18.1.2-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:c7d1c604-5b62-5281-935b-8c42480e0ac3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.1.2-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:45f9e975-8ef3-57a5-bc43-539ab2aefcfd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.1.2-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:5cd045e8-ff12-52fb-9323-2c4278479483",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.1.2-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:135ca502-d89e-56fe-ad05-d10c9a5a5c29",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 18.1.2-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:8d7cd2d8-7366-5060-b87f-511ec8538109",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 18.1.2-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:df9d704a-e771-575a-b2af-fcf45707a778",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 18.1.2-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:fbe23f46-b726-5cf4-a8f0-101fb2c468d1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 18.1.2-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:02f7dacc-d695-5db1-a792-a7cd7d97cc6d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 18.1.2-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:bd677bf5-8576-5795-9636-a455d2b859bf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 18.1.2-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:89a18bdc-bbb8-5104-b008-77083d7280f8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 18.1.2-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:b741fbc6-cdaa-54b8-ae6d-cca3457e0240",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50555 does not affect version 18.1.2-tuxcare.7 of @angular/platform-server. already_fixed \u2014 The target Angular 18.1.2 repository has already been patched for this vulnerability. TuxCare commit 32991dd728 'fix all CVEs' added a cumulative domino patch that fixes both the NOSCRIPT XSS vulnerability (CVE-2026-50556, corresponding to the provided patch f74cccd) and the astral Unicode index bug (CVE-2026-50555). The patch is applied automatically to the domino dependency via patch-package ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:c8a520fc-749c-52e1-820f-f529e66ebc50",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50556 does not affect version 18.1.2-tuxcare.7 of @angular/platform-server. already_fixed \u2014 CVE-2026-50556 (XSS via noscript raw-text serialization in domino) has been fixed in this Angular repository. The fix is present in tools/esm-interop/patches/npm/domino+2.1.6.patch and is automatically applied to the domino dependency during installation via the postinstall script. The patch was added by TuxCare in commit 32991dd728 on 2026-07-01.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:3e43e434-de24-569d-aa68-3a34a45754b5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 18.1.2-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:292899de-23b8-581b-8753-adc5a71048b2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 18.1.2-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:3e424475-c22e-56bf-a2ba-651326db55c4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 18.1.2-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:bcbe2ba1-0704-5a5f-b49c-8f9b11cf68ce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 18.1.2-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:4dcae35a-1133-5432-882d-956cada7f7cc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 18.1.2-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:da3e64ea-31a9-5444-a869-6a2e142df818",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 18.1.2-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:7596355a-d320-59b5-9d3f-12112551d167",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 18.1.2-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:a62d721d-7a8f-5d8e-b556-ff4a799e9088",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 18.1.2-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:ee45413a-2994-574c-948e-ad58851b1787",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 18.1.2-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:63ff1f4d-f23a-54b7-885f-60e8cf5e3404",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 18.1.2-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:64513752-c433-5b9e-b5da-22a8782de307",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.1.2-tuxcare.7 of @angular/platform-server. not_affected \u2014 The target version (Angular 18.1.2) does NOT contain the vulnerable code pattern. CVE-2026-88056 describes a Unicode whitespace trimming vulnerability in Angular SSR's URL resolution, where `String.prototype.trim()` strips characters like U+00A0, converting same-origin paths into protocol-relative cross-origin URLs. The vulnerability was introduced in Angular v20.x during a refactoring (commit ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:b0022b08-b044-5690-83d6-816feb09fb0a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 18.1.2-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:f3167314-7f0f-5ac7-96a5-7f2abdcd0caa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 18.1.2-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:90b3c0da-7a02-5312-9115-25a39a433e04",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 18.1.2-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:3af6a5b9-2f6c-5c32-9085-935d524768fd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 18.1.2-tuxcare.7 of @angular/platform-server."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.7"
    }
  ]
}