{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:48b92a8c-572b-570d-be6f-21e4fb15b04b",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/common",
      "purl": "pkg:npm/%40angular/common@17.1.0-tuxcare.5",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5",
      "version": "17.1.0-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:833ad59d-1dd9-5c97-9eff-828c94b99c81",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.1.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a3feef97-c6b9-5dff-999d-f19b68c126df",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.1.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e569c359-0cce-58e0-b06e-f036c3ad2be2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.1.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0c3b81b2-4938-5a08-93d8-beefb3ad5501",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.1.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c2d34245-6735-50a1-b3e5-29a2ee5fafaf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.1.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5f400e85-211a-54c0-8807-d8351de1aaed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.1.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d772f78e-699d-5347-a7bb-4d1f6ec39237",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 17.1.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:bfd2f46d-9d25-58f1-838f-f21eb4281cce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.1.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0263a27d-47ae-5814-a3ee-adf476f1dcb1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.1.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:fe621d10-f2d0-5fe0-aadb-bfd4edcc18ea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.1.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2a65ee87-c562-55ad-80fa-c3ef6677b4b9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.1.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4cffc133-6af7-5671-87a0-4e00b5a1e73c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.1.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6ac26813-ef1e-580d-b28a-82e6458fdcb5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.1.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:19305d91-7fc0-524e-a222-6d618903b682",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.1.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:94ba4b9c-b63d-5e8d-b2cf-bf06cc3251c6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.1.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1bcfda70-3469-5f6d-84c1-5993d9538e0b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.1.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d5b419e2-974d-51e5-b0b1-562febb0557e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.1.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:cdfcbaf7-ae9a-5cfd-8c6b-52d3fa0a2df6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.1.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1f1eeddf-c79d-5a84-9257-c6cebb3386bd",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 17.1.0-tuxcare.5 of @angular/common. not_affected \u2014 Angular v17.1.0 does not have the TwoWayProperty IR operation that is the subject of CVE-2026-54265. Two-way bindings are desugared into separate property and event bindings before template pipeline processing, with the property half using the same parsePropertyBinding() code path as one-way property bindings, which are properly sanitized.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:bbcc88d0-3cff-52b4-ae0a-7e8bdbf1e127",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.1.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:85302164-7c80-5ddc-99b6-d9900b091910",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.1.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2c447461-654f-50a8-8a57-e56aeb2c03eb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.1.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ec1c42d9-e563-564c-9889-5c96ede70181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 17.1.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9aa6a569-fe8e-5e28-b23e-32be9d42500c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 17.1.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3902cfaf-cd58-5f46-b401-4a42c895eb56",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 17.1.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:10b5cbbc-523b-52ee-be7a-a145b7a5de6e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.1.0-tuxcare.5 of @angular/common. not_affected \u2014 Angular 17.1.0 was never vulnerable to CVE-2026-88056. The vulnerability exists only in newer Angular versions (v18+, v19+, v20+ before fixes) where a url.ts file with a parseUrl function that uses String.prototype.trim() was introduced. Angular 17.1.0 does not have this file in the upstream release. TuxCare created url.ts for their 17.1.0 fork (commit e06d36f339 by ejarocki@cloudlinux.com) but...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:dee9b75c-1d11-5511-ad86-09c3e7a7e178",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 17.1.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7ac45fbf-8d61-5e3a-a393-9e73fb5c6333",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 17.1.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f327e503-11d7-5c9c-a3e7-340717efd18f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 17.1.0-tuxcare.5 of @angular/common."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.5"
    }
  ]
}