{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:883276ec-aec1-5e40-8380-25818a09856e",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/compiler-cli",
      "purl": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.10",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.10",
      "version": "16.2.12-tuxcare.10",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:66cc8b82-9107-5dca-8205-52baa0609628",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 16.2.12-tuxcare.10 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:510251db-6023-56ff-838d-ad62a7d50e98",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.12-tuxcare.10 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:dc5dbffd-6dea-5414-9c5c-a0c6a8a0b3a8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 16.2.12-tuxcare.10 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:88e0f428-4f49-5714-a73d-e6d157134110",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 16.2.12-tuxcare.10 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:7c76b069-1ad4-5a15-a31c-931b8a5bce71",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 16.2.12-tuxcare.10 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:ea52dda3-4273-5209-bf16-b2e2dfb174dd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 16.2.12-tuxcare.10 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:a612a6d1-8b78-5eea-a6fd-70f6436cac1d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 16.2.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:82cab492-d078-5470-bea4-9eb793cf4e89",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 16.2.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:30ae07ff-fbf8-5107-a663-6a35e39f4ffc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 16.2.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:a5bd40f4-3bc8-5403-b993-2d026e83b683",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 16.2.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:1addc51e-8d15-50fe-8435-ba52a55dbaf3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 16.2.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:765b0b87-2e93-55e4-ba18-064ece8af8d4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 16.2.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:932356db-f8ea-580a-a772-db0ba4301d43",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 16.2.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:345c9e2a-0c16-50f0-ba6f-1de196b0014c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 16.2.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:899948ad-3fbf-5b71-b4af-9f155ce6fd41",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 16.2.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:7be4259b-75d3-506f-b0b3-b33251465861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 16.2.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:57de4c55-01ac-575f-bc89-81ff9f58d6bf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 16.2.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:bb0996f6-8a2c-5a23-9635-52c33f2aea42",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 16.2.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:052a0708-3fe2-5434-8b07-57e2b961d9ee",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 16.2.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:18f07bc8-7792-5788-9676-3c1686e27657",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 16.2.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:ed6cc43d-5525-5aaf-bb91-ebd1326912e2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 16.2.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:f93d0b2a-01c7-5e02-8de7-dce3c01898c0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 16.2.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:da73bf33-bce1-509b-96f1-87278cb383a2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 16.2.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:a135a15c-86c8-5445-94b6-fed10aa3dd23",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.12-tuxcare.10 of @angular/compiler-cli. not_affected \u2014 CVE-2026-88056 affects Angular versions 20.3.x, 21.2.x, and 22.x where a refactored URL parsing utility added String.prototype.trim() that strips Unicode whitespace, enabling SSRF bypasses. The target (Angular 16.2.12-tuxcare.12) is based on Angular 16.2.x architecture, which predates the vulnerable code pattern entirely. TuxCare created url.ts fresh on June 24, 2026 for CVE-2026-50168, modelin...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:78d7792c-1aa1-548e-ad3d-65038f9d7ea7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 16.2.12-tuxcare.10 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:785ace2f-2213-5f2c-90fc-3a0621da2df6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 16.2.12-tuxcare.10 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:bc759010-6a98-54a8-bb67-3c85428307f5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 16.2.12-tuxcare.10 of @angular/compiler-cli."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.10"
    }
  ]
}