{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a8544046-2296-5ab9-b32e-377354b6fbe3",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/platform-server",
      "purl": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8",
      "version": "18.1.2-tuxcare.8",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:596640b6-baff-54c4-a497-19daa988d70a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 18.1.2-tuxcare.8 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:806d70c0-1313-5adf-b886-0fda7c89cedb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:7e0f682c-d549-502e-b4b9-60144015ab93",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:5364ab42-6401-51cf-afad-99edbf6c4a18",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:d3a02def-9228-5aa7-bfe4-2c52a9ab67f9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 18.1.2-tuxcare.8 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:c4ee7304-674a-5519-bf38-bc4652565955",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:0c04abb0-86ac-5c16-98dc-b8bc5c89aae8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:3fd9a268-5dbd-5e32-b9d9-2d323725a285",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:d8f2766f-7487-5d2b-934c-71aa9bcf89f7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:997406d2-b9ed-5719-a611-7ccfb5f373c7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:8a6d66df-cd13-5877-b25e-7edc23f191e6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:bc13a9e0-1933-5ffb-bfa1-4da36b35c4d8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:ffcfe7a4-29e3-5f39-897d-452a2a66b886",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:519448ec-506e-53d8-927a-1c9b6dbc9432",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:7672eda2-2e04-50f5-82b0-396a7f1f3b7a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:ab296f97-5d43-56fb-929d-a271ea82c59e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50555 does not affect version 18.1.2-tuxcare.8 of @angular/platform-server. already_fixed \u2014 The target Angular 18.1.2 repository has already been patched for this vulnerability. TuxCare commit 32991dd728 'fix all CVEs' added a cumulative domino patch that fixes both the NOSCRIPT XSS vulnerability (CVE-2026-50556, corresponding to the provided patch f74cccd) and the astral Unicode index bug (CVE-2026-50555). The patch is applied automatically to the domino dependency via patch-package ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:4794bfa1-a4cf-50fb-96d9-3ec5c74e68a8",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50556 does not affect version 18.1.2-tuxcare.8 of @angular/platform-server. already_fixed \u2014 CVE-2026-50556 (XSS via noscript raw-text serialization in domino) has been fixed in this Angular repository. The fix is present in tools/esm-interop/patches/npm/domino+2.1.6.patch and is automatically applied to the domino dependency during installation via the postinstall script. The patch was added by TuxCare in commit 32991dd728 on 2026-07-01.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:2061d8ef-fb33-5f16-9b7d-2e44c8cfde96",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:3ac31152-dbc7-58ea-a2e5-26035510df3b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:7c323a62-bff4-5460-af72-a7f3134a14b9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:787cd3e5-3556-540a-9469-569fb0a4cf6f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:17b11e23-307c-5c0f-b3f3-5ee8e4d4174d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:e9cad82d-ac5c-5109-8687-0b5d4875c98e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:48e7af98-4c25-5828-882d-32674e4ff6e0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f1d648cd-2889-593a-9216-16716be7db43",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:936f3eae-d644-56bd-9fb3-30977fa9a623",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:24ab9164-1cb4-557a-9ead-844eaa93aa5e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:e522fb4a-836e-587e-a946-1d49359c7d81",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.1.2-tuxcare.8 of @angular/platform-server. not_affected \u2014 The target version (Angular 18.1.2) does NOT contain the vulnerable code pattern. CVE-2026-88056 describes a Unicode whitespace trimming vulnerability in Angular SSR's URL resolution, where `String.prototype.trim()` strips characters like U+00A0, converting same-origin paths into protocol-relative cross-origin URLs. The vulnerability was introduced in Angular v20.x during a refactoring (commit ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:20a7247f-c223-595b-9a2d-dfe845834871",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:0082cf92-06ca-59e0-b95d-7ae8fd1d2e63",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:0ad12005-3ce8-5c62-88c9-ccfaef491f7e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:77770a56-5177-51fe-8293-117646f56c47",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 18.1.2-tuxcare.8 of @angular/platform-server."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-server@18.1.2-tuxcare.8"
    }
  ]
}