{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:421dc643-86f7-576b-bab1-a0d3d7a904da",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/service-worker",
      "purl": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5",
      "version": "16.2.11-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:01e0c78e-cf95-5ca8-8f9b-7524a015d9ec",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 16.2.11-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a30290b9-291f-548a-8f56-0b97e983d9b3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.11-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:33604e41-196a-5cf3-9bed-8a8936683a09",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 16.2.11-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3929e576-75ee-58e9-94b4-f8bef1553cb2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 16.2.11-tuxcare.5 of @angular/service-worker, and is fixed in 16.2.11-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e483c6d8-01cb-587c-87ac-f9e4e8f9b860",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 16.2.11-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d6a18a9b-1635-5aa0-80ae-3912f3183607",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 16.2.11-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:dbc8df9c-59ae-5557-8b04-7f92b831a23d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 16.2.11-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7a9d2778-cc3f-5cc5-b2ae-a7cc54b3f4fe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 16.2.11-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:166de591-1aa5-58e7-84cd-33fcd9277382",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 16.2.11-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a2f0536c-b896-5547-821b-84339492423f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 16.2.11-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3a8ddd0b-7d5d-50e3-a112-b15578b89d58",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 16.2.11-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:777674f5-a15e-5ec1-922e-f0617ab856ba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 16.2.11-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7783e2b2-11e3-5735-9b4f-e3b4de48ef95",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 16.2.11-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2b43dc61-a470-51d2-b5f5-b493ef1c42ed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 16.2.11-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e32e91b0-9379-506f-9058-b648c14b0b80",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 16.2.11-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9a0c1f77-b91c-5deb-ad0f-10376f2e04e1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 16.2.11-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b53ce70d-eebc-5a7f-905e-3979c828e419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 16.2.11-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:84dd6288-4973-587e-8e4f-ab8893ef5119",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 16.2.11-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4fdd36ff-99cb-58fb-bd44-9ffca90bedc7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 16.2.11-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0d795a99-438c-58db-a51a-939e68c39a72",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 16.2.11-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:85dcceed-0f49-51d4-9b60-5d274b243d66",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 16.2.11-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8e410ef7-21db-5484-ab5d-dafed8d23b15",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 16.2.11-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:38332bd0-42b7-5b74-b2f2-62a1e090a829",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 16.2.11-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e2e05737-ff8a-5d92-b80a-d16a53f72b24",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 16.2.11-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0a728650-38a2-55bc-8edf-1926bb5dd712",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 16.2.11-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:123929a0-c8d5-54fa-96e6-4895d80862f7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 16.2.11-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3b8cbc99-ca67-5458-b5ba-25b7275a1fbe",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.11-tuxcare.5 of @angular/service-worker. not_affected \u2014 Angular 16.2.11-tuxcare.2 is NOT affected by CVE-2026-88056. The vulnerability requires WHATWG URL validation combined with String.prototype.trim() on URLs during SSR, creating a discrepancy that enables SSRF. While the target uses WHATWG URL parsing (backported in commit c03fbfd7cc for CVE-2026-50168), it does NOT call String.prototype.trim() on URLs. The attack chain is broken at the trim() s...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2ae27709-4781-569c-932d-007ec3ef13e0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 16.2.11-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8c1d35ea-dfa6-55d8-b832-71122a220483",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 16.2.11-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6228fe7c-000a-54fc-91eb-8a6749d15e0e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 16.2.11-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f545153d-1bf2-5405-9477-cb0c9d7ce570",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 16.2.11-tuxcare.5 of @angular/service-worker."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/service-worker@16.2.11-tuxcare.5"
    }
  ]
}