{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0d51dc88-3f14-5272-831e-83f556745fc4",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@ngtools/webpack",
      "purl": "pkg:npm/%40ngtools/webpack@19.2.27-tuxcare.1",
      "type": "library",
      "bom-ref": "pkg:npm/%40ngtools/webpack@19.2.27-tuxcare.1",
      "version": "19.2.27-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2026-27738",
      "affects": [
        {
          "ref": "pkg:npm/%40ngtools/webpack@19.2.27-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:63d9a89f-3957-51ee-b2aa-5fbeb8c1623b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-27738 does not affect version 19.2.27-tuxcare.1 of @ngtools/webpack. not_affected \u2014 The target Angular CLI/DevKit version 19.2.27 is not affected by CVE-2026-27738 (Open Redirect via X-Forwarded-Prefix). The upstream vendor fix is already present in the shipped code. Both security defenses are in place: (1) joinUrlParts function strips ALL leading/trailing slashes via while loops (lines 110-116 in url.ts), preventing protocol-relative URL formation like //evil.com, and (2) VAL...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-27739",
      "affects": [
        {
          "ref": "pkg:npm/%40ngtools/webpack@19.2.27-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0cdf8e1f-3892-59d7-b65a-cd1f1ce6ba23",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-27739 does not affect version 19.2.27-tuxcare.1 of @ngtools/webpack. The target repository (angular-cli v19.2.27) is not affected by CVE-2026-27739 (SSRF via unvalidated HTTP headers in Angular SSR). The vulnerability was fixed by the upstream vendor (Google/Angular team) in commit 2a72d7483d87ccdcfa0c5148f34a4c6ebb6c6cf9, authored by alanagius@google.com, which was included in upstream release v19.2.21. The current target version v19.2.27 includes this fix through normal upstream progression (not through a TuxCare backport). The fix introduces comprehensive validation of Host, X-Forwarded-Host, X-Forwarded-Port, and X-Forwarded-Proto headers, blocking malicious header values before they can be used to construct URLs for server-side HTTP requests.",
        "justification": "code_not_present"
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40ngtools/webpack@19.2.27-tuxcare.1"
    }
  ]
}