{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b74ba329-85c0-5818-838e-7c03a0c1fb9b",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/benchpress",
      "purl": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.2",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.2",
      "version": "16.2.12-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:38a8ac2e-56d9-5474-a32b-e2e3674ceaf4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 16.2.12-tuxcare.2 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c7447ae4-0288-5258-8c0e-ec98cb5a4d16",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.12-tuxcare.2 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7a04cd32-e3ef-59a1-99da-b0703d4a1033",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 16.2.12-tuxcare.2 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8e9a8b15-0ac9-52e9-99c6-7d3781d222cf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 16.2.12-tuxcare.2 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:643282d7-6127-5cc3-b920-4d19080f3a5d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 16.2.12-tuxcare.2 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e5a31967-2ec2-5eda-9c93-a26b7f3f15db",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 16.2.12-tuxcare.2 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.10."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7046fc95-f206-575e-8a89-b9623fed3696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 16.2.12-tuxcare.2 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1e43808b-8089-5a21-bb07-564c49f7e596",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 16.2.12-tuxcare.2 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c570d54e-ec39-5b80-9add-e22e766487b3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 16.2.12-tuxcare.2 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2af00baa-444d-5d1c-b210-117624d88cff",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 16.2.12-tuxcare.2 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c1f52874-8cdf-549f-8830-b4608bdf6a52",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 16.2.12-tuxcare.2 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:463acc1e-0b0c-5074-bf84-fe44c3cac15e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 16.2.12-tuxcare.2 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7f799b6a-dfda-5cef-86fc-b65c6d0964c6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 16.2.12-tuxcare.2 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a418f3f0-1208-5eca-bba3-ed6d5577123d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 16.2.12-tuxcare.2 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:54bd83c8-234f-5886-8d1c-cdb83ed812f8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 16.2.12-tuxcare.2 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:66b09e37-01a9-5b42-8bc9-eacc2f0f18e5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 16.2.12-tuxcare.2 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:62236533-d234-55b3-aae8-b76572d26695",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 16.2.12-tuxcare.2 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d6fb3ce3-0f8f-5025-8af5-d2f9ebe12da1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 16.2.12-tuxcare.2 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0af7de04-8b4c-50ab-8a4f-3b2528cd9cb7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 16.2.12-tuxcare.2 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d9cfe0a2-c2bc-551e-b066-9138cb042750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 16.2.12-tuxcare.2 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c853b051-cb3c-52ce-af29-0e9dab150a45",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 16.2.12-tuxcare.2 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3ff45a53-88a7-59c1-948b-1ca87bf5e834",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 16.2.12-tuxcare.2 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1c94d79b-680d-50f9-b0f2-1373db542598",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 16.2.12-tuxcare.2 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:165e2a24-6961-5641-9053-252cf3414a48",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.12-tuxcare.2 of @angular/benchpress. not_affected \u2014 CVE-2026-88056 affects Angular versions 20.3.x, 21.2.x, and 22.x where a refactored URL parsing utility added String.prototype.trim() that strips Unicode whitespace, enabling SSRF bypasses. The target (Angular 16.2.12-tuxcare.12) is based on Angular 16.2.x architecture, which predates the vulnerable code pattern entirely. TuxCare created url.ts fresh on June 24, 2026 for CVE-2026-50168, modelin...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:af85cad2-f8f0-5b6c-8320-58dc64be895b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 16.2.12-tuxcare.2 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:68ab740a-1170-5a6a-bb88-02a78a0801cf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 16.2.12-tuxcare.2 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:261c97d4-9425-5a23-9167-0b6a38648642",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 16.2.12-tuxcare.2 of @angular/benchpress."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.2"
    }
  ]
}