{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:05f95f9e-1cab-5f57-b920-04aec38ff0e7",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/bazel",
      "purl": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.6",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.6",
      "version": "8.2.14-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:bd719d3d-1073-565b-9a88-11e4ac75c0d4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 8.2.14-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:73347b86-944d-5d41-82f2-6c456e983883",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 8.2.14-tuxcare.6 of @angular/bazel, and is fixed in 8.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8b65e16a-04ab-5a56-b9ca-44c5d15680a6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 8.2.14-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7de5e99e-54ce-53e3-b9b3-aff82f59bb12",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 8.2.14-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1b00d319-eece-590d-accd-bb2f53e4b63c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 8.2.14-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0932ae2d-0268-55d0-9da8-a2b1cbffcfcb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 8.2.14-tuxcare.6 of @angular/bazel, and is fixed in 8.2.14-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2c441844-d5c7-5aa2-a6ad-f5a800d992ec",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 8.2.14-tuxcare.6 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1ea5494e-8785-51dd-927a-cca5a3348c76",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 8.2.14-tuxcare.6 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d81b9daa-b482-5f25-a1c5-abe790415897",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 8.2.14-tuxcare.6 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c75d4bdd-88a5-5e89-9dab-be3678979c7b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 8.2.14-tuxcare.6 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5478d7aa-df84-51ad-ba80-defbae80d8a6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 8.2.14-tuxcare.6 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:76d188a9-59b6-5dad-95df-4d82b2a8a157",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 8.2.14-tuxcare.6 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4fe59d54-b37d-595f-8f01-916f565346b4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 8.2.14-tuxcare.6 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9ec13143-9785-5dfb-863a-5b1a905df8b7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 8.2.14-tuxcare.6 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4418cc88-5f61-5bb4-8858-067be6bf1b2b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 8.2.14-tuxcare.6 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:341d6fcd-785c-5c46-a067-c404e766e400",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 8.2.14-tuxcare.6 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5342ebd2-d7fe-5f18-9121-50702bf5af94",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 8.2.14-tuxcare.6 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:13f2def5-62b9-515e-8b9a-ef260853b028",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 8.2.14-tuxcare.6 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3b4fa2ae-67e0-55b9-aec0-59f60339cc75",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 8.2.14-tuxcare.6 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f3be49e4-c9cb-5e74-a291-08434dd4ce4b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 8.2.14-tuxcare.6 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4fccdcd9-cac5-5a46-97e4-776de0874819",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 8.2.14-tuxcare.6 of @angular/bazel. not_affected \u2014 Angular 8.2.14 is NOT affected by CVE-2026-68945. The vulnerability exists in HttpTransferCache, a feature that automatically caches HTTP requests during SSR for client hydration. HttpTransferCache was introduced in Angular v16+ and does not exist in version 8.2.14. This version has only a manual TransferState key-value store with no automatic HttpClient integration, and no HTTP caching mechani...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3f806a15-885f-5784-a3b8-9bbb4582aabc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 8.2.14-tuxcare.6 of @angular/bazel, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f17a2ff6-bc5a-5d63-be99-3f24faa35745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 8.2.14-tuxcare.6 of @angular/bazel, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:513ff636-c42c-59ac-9737-a436cde3ac2e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 8.2.14-tuxcare.6 of @angular/bazel. not_affected \u2014 Angular 8.2.14 is NOT AFFECTED by CVE-2026-88056. The vulnerability requires a sophisticated URL resolution utility (`parseUrl` in `packages/platform-server/src/url.ts`) that calls `String.prototype.trim()` to strip Unicode whitespace, creating a discrepancy with WHATWG URL validation. This architecture was introduced in Angular v12+ (circa 2026 as TuxCare backports). Angular 8.2.14 (released N...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7d86e986-8323-5a1a-ab36-fd1135de38e6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 8.2.14-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:29c95b8f-66d0-5036-86ff-c0949c90e82b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 8.2.14-tuxcare.6 of @angular/bazel. not_affected \u2014 Angular v8.2.14 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, provideClientHydration(), and withRequestsMadeViaParent() \u2014 all features that do not exist in this version. These features were introduced in Angular v16 (per patches/CVE-2026-50170.patch and patches/CVE-2026-54266.patch). The target uses the legacy NgModule-based HttpClientModule without automatic ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e535a63a-24ce-57d8-bfaf-dba9f7bfc79a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 8.2.14-tuxcare.6 of @angular/bazel."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.6"
    }
  ]
}