{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2cfb6260-ff67-544b-a834-681ca4694f4f",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/bazel",
      "purl": "pkg:npm/%40angular/bazel@12.2.17-tuxcare.3",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/bazel@12.2.17-tuxcare.3",
      "version": "12.2.17-tuxcare.3",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:782471fd-0d54-5dbb-9b28-812e43f5a4d7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 12.2.17-tuxcare.3 of @angular/bazel, and is fixed in 12.2.17-tuxcare.8."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:d51681b5-58be-581a-a9ef-b10780806613",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 12.2.17-tuxcare.3 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:340418be-8039-57e2-834e-06c638f8b22a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 12.2.17-tuxcare.3 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:b2a097d0-f538-5470-b498-56aceff20a9a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 12.2.17-tuxcare.3 of @angular/bazel, and is fixed in 12.2.17-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:8e5d875c-9916-5ade-8e2e-3ceb6cc366fd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 12.2.17-tuxcare.3 of @angular/bazel, and is fixed in 12.2.17-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:67c974f6-9d8d-54d7-b3e0-8e6673fe01cf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 12.2.17-tuxcare.3 of @angular/bazel, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:7983c563-e34e-589b-8cb9-0be4950fe079",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 12.2.17-tuxcare.3 of @angular/bazel, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:3fe9a5c6-55f3-534f-be9e-a3c79cb6e5b3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 12.2.17-tuxcare.3 of @angular/bazel, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:e5928318-8d13-5edd-924b-7d3665fe603c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 12.2.17-tuxcare.3 of @angular/bazel, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:067e9995-ec2a-5c11-8a93-30071b1c8787",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 12.2.17-tuxcare.3 of @angular/bazel, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:b51910c6-e612-5056-8065-2e2ab6d664c1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 12.2.17-tuxcare.3 of @angular/bazel, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:10ac84b2-f58c-5c99-8ff1-b33d2fb4ebd0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 12.2.17-tuxcare.3 of @angular/bazel, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:51c98ad7-76cf-58b0-a0ab-062499f1a8d7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 12.2.17-tuxcare.3 of @angular/bazel, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:ba5b25ee-4568-59a3-941a-2443974307f4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 12.2.17-tuxcare.3 of @angular/bazel, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:6554db5c-d73d-544a-82fe-18450f134387",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 12.2.17-tuxcare.3 of @angular/bazel, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:f662d5cf-8826-505e-9c1b-4a17b8e5d19c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 12.2.17-tuxcare.3 of @angular/bazel, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:3c6edb97-7622-5687-9707-eb13e0b057a0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 12.2.17-tuxcare.3 of @angular/bazel, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:59bfd279-de40-52dd-94b0-144299993576",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 12.2.17-tuxcare.3 of @angular/bazel, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:cb1b1925-7ef6-5b60-a59b-058cbc733cc1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 12.2.17-tuxcare.3 of @angular/bazel, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:918cebfc-fe45-57f9-b14a-02fc7bbc5fb0",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 12.2.17-tuxcare.3 of @angular/bazel. not_affected \u2014 Angular 12.2.17 does not contain the HttpTransferCache feature affected by CVE-2026-68945. HttpTransferCache, which caches HTTP requests during Server-Side Rendering (SSR), was first introduced in Angular 16.0.0\u2014approximately 4 major versions after the target version. The vulnerability concerns cache-key collision when repeated HTTP parameters are serialized, but since the entire HttpTransferCa...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:9db029bb-b967-5521-a09e-9563a9d44dbf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 12.2.17-tuxcare.3 of @angular/bazel, and is fixed in 12.2.17-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:1e296ad3-4357-5d10-a046-0a01c036c95e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 12.2.17-tuxcare.3 of @angular/bazel, and is fixed in 12.2.17-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:02606f15-4f6d-534d-af6d-bfe0f0b1779c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88056 affects version 12.2.17-tuxcare.3 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:c1b86d95-39d4-5b2d-a690-454f54f33b24",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 12.2.17-tuxcare.3 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:c7422a67-1a67-56f3-b8f2-908613c4212c",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 12.2.17-tuxcare.3 of @angular/bazel. not_affected \u2014 Angular 12.2.17-tuxcare.9 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, withRequestsMadeViaParent(), and provideClientHydration() features which were introduced in Angular 16.0.0. This version uses the older module-based HttpClientModule system and lacks the entire SSR hydration transfer-cache infrastructure. The vulnerable code pattern described in the CVE do...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:e92cb2ee-14c4-5e16-91a3-ba579b337ca2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 12.2.17-tuxcare.3 of @angular/bazel."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/bazel@12.2.17-tuxcare.3"
    }
  ]
}