{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c061166f-4b96-5b1b-8265-59d5fd1c5bbd",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/core",
      "purl": "pkg:npm/%40angular/core@18.2.14-tuxcare.14",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.14",
      "version": "18.2.14-tuxcare.14",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:acfceff3-e5b0-589b-b940-39ddfc3fb7e6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:7a61ee30-9a33-5332-a276-c95f5fec7cb7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:f7e377d9-7e97-5af1-8d49-f41654aeaeb8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:dd303db0-acc3-5899-ad1e-502e4c4923be",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:ca1bb393-6a3a-5fa0-a43a-a59c27f911c3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:2f7ba1ba-ab93-57bf-a299-597a0ad5aa71",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 18.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:15b3ff9e-e46a-5dd1-984f-62e6186b2f4e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 18.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:2e249da5-a33c-577b-9eb6-84fae95bde5b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 18.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:50514812-9e7d-5365-bcf1-ed6e18573f57",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 18.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:74006362-ee1f-560b-979e-af389e5e667a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 18.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:097632ab-9282-5eba-85ab-757075a7b423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 18.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:eddba596-e636-570c-bfe2-a9709d1e115f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 18.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:d88c5275-d7be-5243-b694-131c32ed0513",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 18.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:8a1bc48d-4bc2-5a3d-a9b0-cf79bb0eed3d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 18.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:e9be37d6-edc2-5879-b948-1504b24696e1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 18.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:31c7462f-9e10-5aa4-b179-c9b318acb9e0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 18.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:191116ba-131d-5bdf-a18e-dfa04251d0c4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 18.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:83f152d2-a501-561c-9fd2-8716077a7450",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 18.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:2cacf7df-01df-5610-bbdf-f7fb9507d434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 18.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:b8ae2b33-56da-5d54-8674-4e5fddb5e2cc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 18.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:21ffde20-7fff-5c5b-87a7-9cc6ecdd78c4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 18.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:466aaf00-afab-5565-a207-7bd46cc4bf78",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 18.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:55fd82af-7157-5cfd-ba42-8be205b410bf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 18.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:b036ae0b-8f14-56eb-9aa9-4ae21049691b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.2.14-tuxcare.14 of @angular/core. not_affected \u2014 The target version 18.2.14-tuxcare.13 is NOT affected by CVE-2026-88056. The vulnerable code pattern (calling String.prototype.trim() on URL strings before resolution) was never present in this version. The target uses a refactored parseUrl() implementation introduced via commit 49a60f6045 (May 2026) that correctly handles Unicode whitespace by percent-encoding it rather than stripping it, main...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:14891f5e-ba8d-5920-927d-7abb5a06e491",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 18.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:22f80a67-99bb-52ca-9881-2fa647070dbb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 18.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:b90bd51f-9e1e-531a-8f5c-fa5ef4baf7fb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 18.2.14-tuxcare.14 of @angular/core."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.14"
    }
  ]
}