{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c5fe5faa-19c6-50db-85b3-73bb8df14162",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/benchpress",
      "purl": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.8",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.8",
      "version": "16.2.12-tuxcare.8",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:1fc12d1f-2604-5c5f-99bf-c1e5b2935bb2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 16.2.12-tuxcare.8 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:b67e0c3a-c543-5a2f-bbea-78685af9b8a1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.12-tuxcare.8 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f4cd305e-a6ea-5e17-9e7f-dc91d54f9253",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 16.2.12-tuxcare.8 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:8c13276f-6ed5-535c-be05-35149a64c5ef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 16.2.12-tuxcare.8 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:887f294f-4fac-5340-9282-7dc0a650cadb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 16.2.12-tuxcare.8 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:7f9e8f13-d83f-5433-bff4-ae6ef293f85d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 16.2.12-tuxcare.8 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.10."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:08afd899-8c9c-5c9e-bd12-bb499a311e4f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 16.2.12-tuxcare.8 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:c7701448-0bde-5c3b-98cd-d3d8339c72c1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 16.2.12-tuxcare.8 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:e989db32-cd00-5b2a-8714-145efdbc2b58",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 16.2.12-tuxcare.8 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:377153a4-afb2-50e0-b789-5df49aafa4c8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 16.2.12-tuxcare.8 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:c9d43fbf-f586-5cd5-9ddc-d60d3a083fb9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 16.2.12-tuxcare.8 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6db7f857-4f9d-5699-925b-f25e41140a9c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 16.2.12-tuxcare.8 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:dfd4aec9-01c8-59b8-b0c7-79c09edd8ac8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 16.2.12-tuxcare.8 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6a8eef25-54aa-566c-80e8-243a630d354a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 16.2.12-tuxcare.8 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:13647cc6-29c5-5f89-aa5d-97091d0b30f4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 16.2.12-tuxcare.8 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f1caab1b-5618-5d3b-b25f-2d39015d320f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 16.2.12-tuxcare.8 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:cf72d6d4-274e-5f92-8370-479b33ac003d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 16.2.12-tuxcare.8 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:3d235d08-bb61-539f-9f45-62c93b7208fe",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 16.2.12-tuxcare.8 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:93b59f4f-c16b-5208-a920-cf96d6e01e0a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 16.2.12-tuxcare.8 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:0137851c-79a6-56e7-ba25-fc95eadb725c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 16.2.12-tuxcare.8 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:1c6815db-9a4b-5963-870d-0baaeab449f1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 16.2.12-tuxcare.8 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:d76bb58e-decc-5e30-8d5e-9d7b700c2210",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 16.2.12-tuxcare.8 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:d54a4d0c-b634-5b5b-80b2-ca399c2690a7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 16.2.12-tuxcare.8 of @angular/benchpress, and is fixed in 16.2.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:05cc6a0e-25c1-532e-beff-e4468283d98b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.12-tuxcare.8 of @angular/benchpress. not_affected \u2014 CVE-2026-88056 affects Angular versions 20.3.x, 21.2.x, and 22.x where a refactored URL parsing utility added String.prototype.trim() that strips Unicode whitespace, enabling SSRF bypasses. The target (Angular 16.2.12-tuxcare.12) is based on Angular 16.2.x architecture, which predates the vulnerable code pattern entirely. TuxCare created url.ts fresh on June 24, 2026 for CVE-2026-50168, modelin...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:de4b7078-557b-5ac8-a66a-8d24db872891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 16.2.12-tuxcare.8 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:27321ef7-466a-53cf-ba39-a608d489a617",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 16.2.12-tuxcare.8 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:7f8af5eb-a9af-503b-9396-40c74f789e65",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 16.2.12-tuxcare.8 of @angular/benchpress."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.8"
    }
  ]
}