{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ca36c5d1-b529-58fc-89da-8067020520aa",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/benchpress",
      "purl": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.12",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.12",
      "version": "8.2.14-tuxcare.12",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:18e962d7-3c03-58de-9406-2bb8d49582fb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 8.2.14-tuxcare.12 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:b671a216-c002-5103-9a15-cb85189956e2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 8.2.14-tuxcare.12 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:27b5e839-b7dd-553d-9fce-38ee6cd93737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 8.2.14-tuxcare.12 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:1f8cdff1-8ea8-5c67-ba15-48032b9c0458",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 8.2.14-tuxcare.12 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:afb688ab-cbb1-5115-8401-4b52feac9925",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 8.2.14-tuxcare.12 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:face066e-a3a7-50ba-90bd-b01c227c1cc1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 8.2.14-tuxcare.12 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:2f74efe3-fcac-560e-bba5-a7ef14add9e4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 8.2.14-tuxcare.12 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:7ef29c0c-a6a9-513a-aba1-76651fd8e6b2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 8.2.14-tuxcare.12 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:5acd22b7-fc24-5540-bfe0-4d8a33406c5c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 8.2.14-tuxcare.12 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:be5f3c34-fbf0-5267-af7a-5d83a3ccebaf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 8.2.14-tuxcare.12 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:d78a9ae0-e07e-5e4d-b5ad-7e8e6fbf6cf1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 8.2.14-tuxcare.12 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:85af52d2-7fbc-5dda-a702-ad5d7b19e7d3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 8.2.14-tuxcare.12 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:559597e7-2103-56d2-bcf2-e824cbc98735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 8.2.14-tuxcare.12 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:9835000c-30b2-59f7-83ec-c8ded9676522",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 8.2.14-tuxcare.12 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:417e2546-b810-51fe-bff9-08f7b99874ac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 8.2.14-tuxcare.12 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:9a9c71ad-48db-52a4-ba8c-614bad94b31a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 8.2.14-tuxcare.12 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:ab7aed6f-e681-5c18-acfc-f38f74e61cb2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 8.2.14-tuxcare.12 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:076fd48a-30a0-5d01-a779-4d8d65b1bed1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 8.2.14-tuxcare.12 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:45feadb3-5b21-5694-8960-6d8e287d3c7b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 8.2.14-tuxcare.12 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:48d2f3cc-608a-51b2-ad83-d86717f27e26",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 8.2.14-tuxcare.12 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:a04005b7-4bd6-513a-903a-185dd5f1cb1a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 8.2.14-tuxcare.12 of @angular/benchpress. not_affected \u2014 Angular 8.2.14 is NOT affected by CVE-2026-68945. The vulnerability exists in HttpTransferCache, a feature that automatically caches HTTP requests during SSR for client hydration. HttpTransferCache was introduced in Angular v16+ and does not exist in version 8.2.14. This version has only a manual TransferState key-value store with no automatic HttpClient integration, and no HTTP caching mechani...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:30018102-6f8e-5718-8957-b6667b72957b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 8.2.14-tuxcare.12 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:b4a24285-a3b6-5cd6-9d9d-4b94f4d29c1f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 8.2.14-tuxcare.12 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:b62ebe29-1a32-5576-85a1-6a3c3e9ddb43",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 8.2.14-tuxcare.12 of @angular/benchpress. not_affected \u2014 Angular 8.2.14 is NOT AFFECTED by CVE-2026-88056. The vulnerability requires a sophisticated URL resolution utility (`parseUrl` in `packages/platform-server/src/url.ts`) that calls `String.prototype.trim()` to strip Unicode whitespace, creating a discrepancy with WHATWG URL validation. This architecture was introduced in Angular v12+ (circa 2026 as TuxCare backports). Angular 8.2.14 (released N...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:5bf51d57-2199-5d6f-b40e-c69170c53c2e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 8.2.14-tuxcare.12 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:23a7defd-2659-5976-9bd9-fcf85e4efb34",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 8.2.14-tuxcare.12 of @angular/benchpress. not_affected \u2014 Angular v8.2.14 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, provideClientHydration(), and withRequestsMadeViaParent() \u2014 all features that do not exist in this version. These features were introduced in Angular v16 (per patches/CVE-2026-50170.patch and patches/CVE-2026-54266.patch). The target uses the legacy NgModule-based HttpClientModule without automatic ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:7238ae83-e47f-5e35-a700-323ecec24867",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 8.2.14-tuxcare.12 of @angular/benchpress."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.12"
    }
  ]
}