{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9527e212-b804-5dd9-abed-b6509e22d927",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/compiler",
      "purl": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.8",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.8",
      "version": "8.2.14-tuxcare.8",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:34eea4ac-3b66-5c5e-85c4-584bbc5f0152",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 8.2.14-tuxcare.8 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f79f3567-8746-51f0-99e3-ed10146a9b3b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 8.2.14-tuxcare.8 of @angular/compiler, and is fixed in 8.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:bf503c5c-ffef-5bb9-80c4-1c7c3a95ce4b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 8.2.14-tuxcare.8 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:b27e326b-6780-524c-a463-c4b6a6ad510e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 8.2.14-tuxcare.8 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:7e35abb1-548d-5007-a1c5-78ce31326c35",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 8.2.14-tuxcare.8 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:65a3c752-44ac-525c-b110-e11658b2301f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 8.2.14-tuxcare.8 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:61369833-08c1-510c-8dcb-cc4d6bc1a35e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 8.2.14-tuxcare.8 of @angular/compiler, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:0f3a4ead-f8a3-5312-a08a-a695773f0018",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 8.2.14-tuxcare.8 of @angular/compiler, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:3d4a162c-6164-56e9-b699-f5ded471e9ae",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 8.2.14-tuxcare.8 of @angular/compiler, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:b109f9b7-7f6c-50c8-b590-55d9fab5acf5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 8.2.14-tuxcare.8 of @angular/compiler, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:2defd272-d36b-51b3-bf48-e6c211d80e38",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 8.2.14-tuxcare.8 of @angular/compiler, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:43a7186f-cecc-5a6a-98ca-3006e38d0ea5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 8.2.14-tuxcare.8 of @angular/compiler, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:7464918b-89d6-5394-a297-66944ae20178",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 8.2.14-tuxcare.8 of @angular/compiler, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:3f195014-b98f-540d-9994-c20df011a4bf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 8.2.14-tuxcare.8 of @angular/compiler, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:00512938-c64b-5699-9428-2f1a696e4747",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 8.2.14-tuxcare.8 of @angular/compiler, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:9cd4ab98-1784-500b-be58-48fb12047d2a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 8.2.14-tuxcare.8 of @angular/compiler, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:b2deef64-4773-5377-b920-5fade96908ae",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 8.2.14-tuxcare.8 of @angular/compiler, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:de070cef-7d28-52b9-ba83-3909b6c8f0d0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 8.2.14-tuxcare.8 of @angular/compiler, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6d9b862c-479f-5438-8840-088ad90ea0fd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 8.2.14-tuxcare.8 of @angular/compiler, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:c343c96a-27dc-5111-b8bf-7cd354ec27d2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 8.2.14-tuxcare.8 of @angular/compiler, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:63bdf288-c207-51cd-836a-e2541ebafd61",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 8.2.14-tuxcare.8 of @angular/compiler. not_affected \u2014 Angular 8.2.14 is NOT affected by CVE-2026-68945. The vulnerability exists in HttpTransferCache, a feature that automatically caches HTTP requests during SSR for client hydration. HttpTransferCache was introduced in Angular v16+ and does not exist in version 8.2.14. This version has only a manual TransferState key-value store with no automatic HttpClient integration, and no HTTP caching mechani...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:85496363-bf05-5eb2-935d-8da7d8e4a0b8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 8.2.14-tuxcare.8 of @angular/compiler, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:99968ad9-b089-5e8d-b722-06958109b25d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 8.2.14-tuxcare.8 of @angular/compiler, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:e196d765-1ed6-55af-a139-d1a255087541",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 8.2.14-tuxcare.8 of @angular/compiler. not_affected \u2014 Angular 8.2.14 is NOT AFFECTED by CVE-2026-88056. The vulnerability requires a sophisticated URL resolution utility (`parseUrl` in `packages/platform-server/src/url.ts`) that calls `String.prototype.trim()` to strip Unicode whitespace, creating a discrepancy with WHATWG URL validation. This architecture was introduced in Angular v12+ (circa 2026 as TuxCare backports). Angular 8.2.14 (released N...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:fdd0e5ad-11f5-506d-b167-ff8c4444e79e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 8.2.14-tuxcare.8 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:d3fb1658-ab59-5348-abcb-b3640c3fa5d5",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 8.2.14-tuxcare.8 of @angular/compiler. not_affected \u2014 Angular v8.2.14 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, provideClientHydration(), and withRequestsMadeViaParent() \u2014 all features that do not exist in this version. These features were introduced in Angular v16 (per patches/CVE-2026-50170.patch and patches/CVE-2026-54266.patch). The target uses the legacy NgModule-based HttpClientModule without automatic ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:8f01ca04-3ed4-5f47-820b-04724aebab65",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 8.2.14-tuxcare.8 of @angular/compiler."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.8"
    }
  ]
}