{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:93ba90c4-4a50-5ed2-b386-bcdc1a36724d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.4",
      "type": "library",
      "name": "@angular/upgrade",
      "version": "18.1.2-tuxcare.4",
      "purl": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a9a32afa-a850-53b2-8f56-06592671899e",
      "id": "CVE-2025-59052",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 18.1.2-tuxcare.4 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16410652-78db-5202-92af-a69a29b8867d",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.1.2-tuxcare.4 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:188390de-27b0-5b02-b6d5-6cc342e9b037",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.1.2-tuxcare.4 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b69ba8c1-0b15-519c-945a-f04253d5d651",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.1.2-tuxcare.4 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f85ec59b-6723-56fe-9e63-a16103f3ed20",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.1.2-tuxcare.4 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89c955b0-e989-5364-9fdf-83d9fc950026",
      "id": "CVE-2026-32635",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.1.2-tuxcare.4 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34aabcc7-1d27-5691-89c8-dd22ddd16fd6",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 18.1.2-tuxcare.4 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ac3dfce-834d-561c-936f-e54511b95bf3",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 18.1.2-tuxcare.4 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a5e88a6-56d9-5305-804c-c84d4793a8f0",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 18.1.2-tuxcare.4 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fa392c5-3ca1-58c6-9656-b12f2922ad69",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 18.1.2-tuxcare.4 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1766d89-878c-5d9e-b274-3110c001eb77",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 18.1.2-tuxcare.4 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e07579ab-c4d6-544b-8616-681db4619816",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 18.1.2-tuxcare.4 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23a71f71-6d70-5683-bdea-33b86fc39172",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 18.1.2-tuxcare.4 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10f7e00f-fb99-5a77-b33f-d203dda7f7b2",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50555 does not affect version 18.1.2-tuxcare.4 of @angular/upgrade. already_fixed \u2014 The target Angular 18.1.2 repository has already been patched for this vulnerability. TuxCare commit 32991dd728 'fix all CVEs' added a cumulative domino patch that fixes both the NOSCRIPT XSS vulnerability (CVE-2026-50556, corresponding to the provided patch f74cccd) and the astral Unicode index bug (CVE-2026-50555). The patch is applied automatically to the domino dependency via patch-package ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a63f2e5f-714e-5e44-bfb3-fde121d1acca",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50556 does not affect version 18.1.2-tuxcare.4 of @angular/upgrade. already_fixed \u2014 CVE-2026-50556 (XSS via noscript raw-text serialization in domino) has been fixed in this Angular repository. The fix is present in tools/esm-interop/patches/npm/domino+2.1.6.patch and is automatically applied to the domino dependency during installation via the postinstall script. The patch was added by TuxCare in commit 32991dd728 on 2026-07-01."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fabc0f4f-0e5b-50df-97f8-fbb39f04fa73",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 18.1.2-tuxcare.4 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:152eb8d6-b608-5e4b-80d5-478166df84e3",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 18.1.2-tuxcare.4 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0b517c4-0855-5dd4-8dc6-5fdcabadd47a",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 18.1.2-tuxcare.4 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:850b50a7-4f7a-5b25-8699-bcb3826df2e8",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 18.1.2-tuxcare.4 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:427c0471-53b4-5ed3-9763-af6c57bacf30",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 18.1.2-tuxcare.4 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6075133c-6f19-599f-b6f7-e6a244abe8ce",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 18.1.2-tuxcare.4 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08bbca43-e76e-53d2-9f25-9d213742822d",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 18.1.2-tuxcare.4 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a93049b-78a7-55e2-b80b-139e679d3627",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 18.1.2-tuxcare.4 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37cf994c-3489-5f58-a3f9-ee04e398f73c",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 18.1.2-tuxcare.4 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19bde83d-d1b5-537a-8d39-6a31abfeeb53",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 18.1.2-tuxcare.4 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.4"
    }
  ]
}