{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2e8c61c7-00ce-532d-a3d1-e1fd233e6861",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/core",
      "purl": "pkg:npm/%40angular/core@12.2.17-tuxcare.4",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/core@12.2.17-tuxcare.4",
      "version": "12.2.17-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8384d6b1-2ea4-5191-9072-5491c5c19fc7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 12.2.17-tuxcare.4 of @angular/core, and is fixed in 12.2.17-tuxcare.8."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:12872db9-fc79-5cb0-a200-2aea01547bd9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 12.2.17-tuxcare.4 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:910fd609-9395-5832-8023-ef6ea7903235",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 12.2.17-tuxcare.4 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:37ec2cd6-a482-5a42-9a37-0535071328d7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 12.2.17-tuxcare.4 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:4055e3a4-f078-5466-936e-edd8b1c90fbd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 12.2.17-tuxcare.4 of @angular/core, and is fixed in 12.2.17-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:4a06d3fc-8cbc-5d9e-80e6-2c253fa94c05",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 12.2.17-tuxcare.4 of @angular/core, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0c34be5e-4782-54ca-b895-72a009907017",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 12.2.17-tuxcare.4 of @angular/core, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1a86e9c5-4dc1-566b-b940-29f0b82bb962",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 12.2.17-tuxcare.4 of @angular/core, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:449be13f-1a9f-5b1c-9978-a2ac9533a388",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 12.2.17-tuxcare.4 of @angular/core, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e11a91ea-5c22-501a-b1d3-02e2be2f0b4f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 12.2.17-tuxcare.4 of @angular/core, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b9178bc2-c46a-5596-bd3f-50954a006d7d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 12.2.17-tuxcare.4 of @angular/core, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:179f6be8-e246-5fe8-a1dd-7d4d660982ce",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 12.2.17-tuxcare.4 of @angular/core, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0d39f6d7-8c14-5705-a1c5-5a6c10f468ba",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 12.2.17-tuxcare.4 of @angular/core, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:21210a3c-c9ab-5256-84d9-6e404c2787bb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 12.2.17-tuxcare.4 of @angular/core, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:39d3e322-c131-5fd3-8ca5-ea18cd1eda87",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 12.2.17-tuxcare.4 of @angular/core, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:28d64431-3ed2-5b03-9e0a-670282e16df0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 12.2.17-tuxcare.4 of @angular/core, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:4b528f29-d79b-5df5-8e33-fa13f4d91383",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 12.2.17-tuxcare.4 of @angular/core, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:15baf15f-558d-5f09-86c9-25dc9b30e756",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 12.2.17-tuxcare.4 of @angular/core, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f703c2ba-6a4e-5ec5-ab7a-37f5fb03d709",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 12.2.17-tuxcare.4 of @angular/core, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:45f1d6ea-0867-5968-b0f3-0391100a6446",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 12.2.17-tuxcare.4 of @angular/core. not_affected \u2014 Angular 12.2.17 does not contain the HttpTransferCache feature affected by CVE-2026-68945. HttpTransferCache, which caches HTTP requests during Server-Side Rendering (SSR), was first introduced in Angular 16.0.0\u2014approximately 4 major versions after the target version. The vulnerability concerns cache-key collision when repeated HTTP parameters are serialized, but since the entire HttpTransferCa...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6c8a94b0-705c-5886-90f1-2f7233727554",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 12.2.17-tuxcare.4 of @angular/core, and is fixed in 12.2.17-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3522c23c-34f2-5356-b016-ef6aeeb6714c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 12.2.17-tuxcare.4 of @angular/core, and is fixed in 12.2.17-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:404164b2-cc3c-564b-93cd-26f5eb722b1d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88056 affects version 12.2.17-tuxcare.4 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:36e4d82e-d6e0-5b85-8a19-73aefa473bea",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 12.2.17-tuxcare.4 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:207b0121-efc6-59f6-a490-945bc8c1653f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 12.2.17-tuxcare.4 of @angular/core. not_affected \u2014 Angular 12.2.17-tuxcare.9 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, withRequestsMadeViaParent(), and provideClientHydration() features which were introduced in Angular 16.0.0. This version uses the older module-based HttpClientModule system and lacks the entire SSR hydration transfer-cache infrastructure. The vulnerable code pattern described in the CVE do...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ff05db13-ebec-5408-a9a6-b4676b5f4609",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 12.2.17-tuxcare.4 of @angular/core."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/core@12.2.17-tuxcare.4"
    }
  ]
}