{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6a9312ce-e9ec-5ae2-bfe3-19d6e80a9e4a",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/service-worker",
      "purl": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7",
      "version": "18.1.2-tuxcare.7",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:ebede84b-524a-56b1-87cd-1485d18bf590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 18.1.2-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:92948beb-838f-5df4-928b-4be98d3459ab",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.1.2-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:80a7164d-d904-5dc6-b374-1bb62429fe68",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.1.2-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:b69e4764-99ce-58d5-8d8b-642072cc65fd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 18.1.2-tuxcare.7 of @angular/service-worker, and is fixed in 18.1.2-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:5a59f89b-6bb5-5b59-b5e2-23aed33dce21",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 18.1.2-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:d617f190-0fbe-532d-b75e-f337ef790f9c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.1.2-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:fe1d6751-aae6-515c-9ada-80e826567bbb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.1.2-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:88d63866-9780-5cc3-b32f-f2a3cb5003a6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.1.2-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:4f7b1725-b1aa-572a-a43b-a4f8996d4c52",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 18.1.2-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:3d1549aa-d39c-52c0-a81c-c249fe73e8b3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 18.1.2-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:6b3fe1ec-d318-50d5-9705-1de369fdf835",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 18.1.2-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:1fdf7c7e-750b-5067-9609-f5f2622e058b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 18.1.2-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:e94573a6-91f6-5b52-82a9-a30e014ce58a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 18.1.2-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:11de3542-b00b-5d45-a7c8-25046074fb44",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 18.1.2-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:bb799506-410f-562a-902f-ad7ce1017a7c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 18.1.2-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:c3118309-f8c2-5630-b5d1-2d38abf4645d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50555 does not affect version 18.1.2-tuxcare.7 of @angular/service-worker. already_fixed \u2014 The target Angular 18.1.2 repository has already been patched for this vulnerability. TuxCare commit 32991dd728 'fix all CVEs' added a cumulative domino patch that fixes both the NOSCRIPT XSS vulnerability (CVE-2026-50556, corresponding to the provided patch f74cccd) and the astral Unicode index bug (CVE-2026-50555). The patch is applied automatically to the domino dependency via patch-package ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:ce60785d-a6e3-5bb1-9141-1e3c3c7604ec",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50556 does not affect version 18.1.2-tuxcare.7 of @angular/service-worker. already_fixed \u2014 CVE-2026-50556 (XSS via noscript raw-text serialization in domino) has been fixed in this Angular repository. The fix is present in tools/esm-interop/patches/npm/domino+2.1.6.patch and is automatically applied to the domino dependency during installation via the postinstall script. The patch was added by TuxCare in commit 32991dd728 on 2026-07-01.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:b14fb045-858f-52fc-be9b-9d9fcc6808d8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 18.1.2-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:5da2545d-e5f0-589c-96d5-fb9f5376b09b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 18.1.2-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:071d37c3-2083-5fc8-8f51-2fbf4413f8f7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 18.1.2-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:4f93f1b3-88ae-5b33-87b5-47d7034c8a4c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 18.1.2-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:4606b148-e44a-59d3-8784-7617078e2cc2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 18.1.2-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:a7650b5a-d19c-5337-9ea6-a63d494683e8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 18.1.2-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:ad27da82-6405-5b6e-8fe0-760c5621c1bc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 18.1.2-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:03cae7c8-c3d9-54e0-ae30-78002c921b96",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 18.1.2-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:6d86a13a-5a92-5647-ae43-0cd9ab7e3edb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 18.1.2-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:39aafbdf-11a7-55f1-aacf-93fa23cc407b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 18.1.2-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:c1aa7792-165c-5d19-93e2-f8806cc81c73",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.1.2-tuxcare.7 of @angular/service-worker. not_affected \u2014 The target version (Angular 18.1.2) does NOT contain the vulnerable code pattern. CVE-2026-88056 describes a Unicode whitespace trimming vulnerability in Angular SSR's URL resolution, where `String.prototype.trim()` strips characters like U+00A0, converting same-origin paths into protocol-relative cross-origin URLs. The vulnerability was introduced in Angular v20.x during a refactoring (commit ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:21b6f936-2aec-5464-81c5-1cf69525bc3d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 18.1.2-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:36a5f4ed-6564-5635-a61c-45e87863e43f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 18.1.2-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:8b653608-68e6-5eaa-ae58-8d222eca27a1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 18.1.2-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:1f3d161d-d82a-58da-9054-eae18d25190d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 18.1.2-tuxcare.7 of @angular/service-worker."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/service-worker@18.1.2-tuxcare.7"
    }
  ]
}