{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0912bcb9-867e-5488-866d-ac54afcbc82c",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/common",
      "purl": "pkg:npm/%40angular/common@18.2.14-tuxcare.14",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.14",
      "version": "18.2.14-tuxcare.14",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:3cf6dd74-c8d1-545f-af42-a2544fcde795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.14-tuxcare.14 of @angular/common."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:d138a22f-3669-5e7c-a5c8-d60d8058a3cb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.2.14-tuxcare.14 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:4304fe3d-081d-5819-949a-1ac9dff1b1fc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.2.14-tuxcare.14 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:a09474a8-6502-5373-b17c-362f4eae2a59",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.2.14-tuxcare.14 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:9550ea5e-2291-5702-8a0a-871c3076d34b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.2.14-tuxcare.14 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:b357d248-ba20-57d2-99b1-c88a0aa4f7ab",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 18.2.14-tuxcare.14 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:03573e6a-864e-576d-a152-66ecd6188fed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 18.2.14-tuxcare.14 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:d8254b4f-f3c5-558e-8fb0-3e26cee6b580",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 18.2.14-tuxcare.14 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:2afc7943-6372-5277-84fe-134c0d77f6b3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 18.2.14-tuxcare.14 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:d70aeea8-5857-5514-917f-f8d722bb4784",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 18.2.14-tuxcare.14 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:54e64daa-0c10-51e3-869c-88677ca71290",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 18.2.14-tuxcare.14 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:80ab038e-1b33-5163-8625-5804e87c0eb6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 18.2.14-tuxcare.14 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:0e0f02ae-2d9c-5328-bb58-ed60b7c3de11",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 18.2.14-tuxcare.14 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:ff237895-d1a3-5a95-9a99-4b164662aa44",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 18.2.14-tuxcare.14 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:18565e4f-d809-590c-8ce0-e8997a092944",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 18.2.14-tuxcare.14 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:c0684047-3b82-55d1-9455-cb08b323f5b3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 18.2.14-tuxcare.14 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:775a983c-c419-518c-8689-33c45660ad12",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 18.2.14-tuxcare.14 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:fea170d6-0cd5-5ade-a7ea-15cdc5ea8704",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 18.2.14-tuxcare.14 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:3fc5d5d1-57da-5659-bd2d-5df88a7278e3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 18.2.14-tuxcare.14 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:badfc38a-8c7a-561a-9bbf-c032995922e0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 18.2.14-tuxcare.14 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:db36085f-dd5b-554d-8b52-fe3df4795b24",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 18.2.14-tuxcare.14 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:b3db9bbd-db7d-560e-a3e9-af224065a636",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 18.2.14-tuxcare.14 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:b65c0898-e4a9-5231-b47b-1bd662fa1c62",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 18.2.14-tuxcare.14 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:70b6c8d5-19e2-5117-8ac7-9155154774d1",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.2.14-tuxcare.14 of @angular/common. not_affected \u2014 The target version 18.2.14-tuxcare.13 is NOT affected by CVE-2026-88056. The vulnerable code pattern (calling String.prototype.trim() on URL strings before resolution) was never present in this version. The target uses a refactored parseUrl() implementation introduced via commit 49a60f6045 (May 2026) that correctly handles Unicode whitespace by percent-encoding it rather than stripping it, main...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:a7e70799-ca98-585e-90cb-0d646d4be757",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 18.2.14-tuxcare.14 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:fd17d220-a433-549a-801a-2d691580e54b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 18.2.14-tuxcare.14 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:e492f4ba-fdc4-547c-a82a-355faa412eb2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 18.2.14-tuxcare.14 of @angular/common."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/common@18.2.14-tuxcare.14"
    }
  ]
}