{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c4245ab5-8e85-51e5-830a-37bdee57a6ac",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/common",
      "purl": "pkg:npm/%40angular/common@18.2.14-tuxcare.1",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.1",
      "version": "18.2.14-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:54075152-1aa3-5431-9f28-4c2077714785",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.14-tuxcare.1 of @angular/common."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cf31ccf6-3799-5bc3-96d3-b84699bc1a4b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 18.2.14-tuxcare.1 of @angular/common, and is fixed in 18.2.14-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a0e3e033-50c6-55df-bd51-7ae649377d37",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 18.2.14-tuxcare.1 of @angular/common, and is fixed in 18.2.14-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cb9428e4-46e6-573b-8786-c8d992795732",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 18.2.14-tuxcare.1 of @angular/common, and is fixed in 18.2.14-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d1ee3620-738f-53a5-8694-1a02509b49f6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32635 affects version 18.2.14-tuxcare.1 of @angular/common, and is fixed in 18.2.14-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1f93d5c7-bc9a-5339-83c0-4a69c51b0a30",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 18.2.14-tuxcare.1 of @angular/common, and is fixed in 18.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:acf56070-bf3c-55f2-8cb6-9a62351a4968",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 18.2.14-tuxcare.1 of @angular/common, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:17f70b7d-8c42-5b73-8f5c-089bb3f8cefd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 18.2.14-tuxcare.1 of @angular/common, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5f140439-4e20-5645-8db4-242b8ab0e32b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 18.2.14-tuxcare.1 of @angular/common, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:aefbeeb9-909a-5d28-8ce0-6dafda11d5f7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 18.2.14-tuxcare.1 of @angular/common, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2afe977f-1eff-5e84-a2c8-8613e38cc088",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 18.2.14-tuxcare.1 of @angular/common, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b009c817-2cf5-56a0-99ca-82e9fb833058",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 18.2.14-tuxcare.1 of @angular/common, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fb08586d-8a91-5b14-8a5f-fd66b5e8af2b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 18.2.14-tuxcare.1 of @angular/common, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:90a19478-8612-5636-b014-f4191ab8c8ba",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 18.2.14-tuxcare.1 of @angular/common, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:84da18cb-5e1e-5221-885d-64f3d9fda105",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 18.2.14-tuxcare.1 of @angular/common, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4fe74a1d-df88-5e0a-8d2b-6c6687cee932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 18.2.14-tuxcare.1 of @angular/common, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b7b30749-0bdb-56e0-bdd7-90d1ac1a5091",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 18.2.14-tuxcare.1 of @angular/common, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1f82836e-830b-5f5c-952f-0083c7a75707",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 18.2.14-tuxcare.1 of @angular/common, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bce4ecd2-5095-549d-80c5-f2c240cefc20",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 18.2.14-tuxcare.1 of @angular/common, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:415407be-6d12-5af5-a3c9-c1bfd2152261",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 18.2.14-tuxcare.1 of @angular/common, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0788c467-c371-5db3-9f56-097cfecf7246",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 18.2.14-tuxcare.1 of @angular/common, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ef17954e-4fa8-54b9-ae87-9eaefe0945dc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 18.2.14-tuxcare.1 of @angular/common, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4dd9b8b5-9237-5945-8330-5d7de993deb0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 18.2.14-tuxcare.1 of @angular/common, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:79838e4f-6105-5948-9e35-204d9870afec",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.2.14-tuxcare.1 of @angular/common. not_affected \u2014 The target version 18.2.14-tuxcare.13 is NOT affected by CVE-2026-88056. The vulnerable code pattern (calling String.prototype.trim() on URL strings before resolution) was never present in this version. The target uses a refactored parseUrl() implementation introduced via commit 49a60f6045 (May 2026) that correctly handles Unicode whitespace by percent-encoding it rather than stripping it, main...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4d2237d2-5c99-53e6-82b4-3865f4f54d64",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 18.2.14-tuxcare.1 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:afe6d933-dc13-5102-808b-4ceb4dbb870f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 18.2.14-tuxcare.1 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f51f86f9-6b37-53b2-9b1e-bdb0b5143a38",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 18.2.14-tuxcare.1 of @angular/common."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.1"
    }
  ]
}