{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3d1d0873-1172-5422-a17b-3dc43de98f01",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/core",
      "purl": "pkg:npm/%40angular/core@17.3.12-tuxcare.5",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.5",
      "version": "17.3.12-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e29c68da-0170-5459-a7ab-bb43ca4eba4e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.3.12-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:685619e9-a1e4-59b4-8d75-70d362994de1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.3.12-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c2b09906-8320-5c0d-93ed-909bcf305822",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.3.12-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e80074b7-a584-5ef4-a449-1d19eac50bbb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.3.12-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:511163d9-6dcb-5385-a088-03b9fbf2ce15",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 17.3.12-tuxcare.5 of @angular/core, and is fixed in 17.3.12-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:55a0f073-5000-51a5-b7f2-8d6ef6cb7335",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32635 affects version 17.3.12-tuxcare.5 of @angular/core, and is fixed in 17.3.12-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:af1ced03-85ae-5fea-ab81-a512bf04a326",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 17.3.12-tuxcare.5 of @angular/core, and is fixed in 17.3.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ec380e9e-6626-5cdd-9bca-ac378d4b7ee6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 17.3.12-tuxcare.5 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ecf26fdd-9450-5bb5-be78-dae14bc3eb67",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 17.3.12-tuxcare.5 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8728f37a-74e0-5be4-a5cf-3e40739156f0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 17.3.12-tuxcare.5 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:eea38912-d145-5ed1-aa4c-5274dd6d3d2c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 17.3.12-tuxcare.5 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0b03a687-375e-580a-991a-447ad4925909",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 17.3.12-tuxcare.5 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:64935ffc-6cb5-5048-84b5-104a4e4b994d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 17.3.12-tuxcare.5 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b107de2b-ce6b-56a0-b53b-96a69a312b9d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 17.3.12-tuxcare.5 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:cb352989-11ee-5ca3-88ba-b049e25b207e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 17.3.12-tuxcare.5 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:43421db2-17a3-50e7-b067-51c7fe8aab6a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 17.3.12-tuxcare.5 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:929bcf76-5ef7-534c-a74a-7d468dea8125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 17.3.12-tuxcare.5 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f9f33ee2-4c1c-50b6-813e-7fb77c593663",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 17.3.12-tuxcare.5 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8cf9ef0d-071d-5843-af81-5f7d5aefc827",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 17.3.12-tuxcare.5 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e1e58cda-b131-5f72-b6c6-9b372f7d8f85",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 17.3.12-tuxcare.5 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c79d1caa-2726-5704-b813-f05e2dd92b85",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 17.3.12-tuxcare.5 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8272471e-6017-55cb-8ab2-cef8b6e5e406",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 17.3.12-tuxcare.5 of @angular/core, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:00b53058-3561-500b-a74a-8a4fe82ff47d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 17.3.12-tuxcare.5 of @angular/core, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:bb439c9f-6ba4-5be0-b703-ad78aae7722c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 17.3.12-tuxcare.5 of @angular/core, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:02647178-2f62-5a07-9a70-95b172716dd3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.3.12-tuxcare.5 of @angular/core. not_affected \u2014 Version 17.3.12 is not affected by CVE-2026-88056. The vulnerability involves String.prototype.trim() being applied during URL resolution in Angular's platform-server, converting validated same-origin URLs with Unicode whitespace into cross-origin protocol-relative URLs, leading to SSRF. This vulnerable code pattern was introduced in newer Angular versions (v20+) and does not exist in version 1...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:08d45003-25be-5e61-a9c7-e16611bbd7b2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 17.3.12-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ebd1661d-8401-5687-be3f-8d05baa49de3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 17.3.12-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f03c9404-a082-597e-84b9-9eb827ea35c7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 17.3.12-tuxcare.5 of @angular/core."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.5"
    }
  ]
}