{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b6fd8632-66cf-586a-9421-73e38177ac7c",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/forms",
      "purl": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5",
      "version": "17.1.0-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:df763456-4fc8-535f-9ee7-43d6ab2e0db5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.1.0-tuxcare.5 of @angular/forms."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5334cd57-72ac-59d3-8da5-204e707f5e5a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.1.0-tuxcare.5 of @angular/forms."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:703f3e2f-b7f8-5dc0-bd01-6a86ee06177c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.1.0-tuxcare.5 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8d693981-d5fa-5e7e-ab01-943066c1f493",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.1.0-tuxcare.5 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8a280818-a4d9-5363-bd71-2d965e3793b5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.1.0-tuxcare.5 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4e9ab1d2-9e88-5de8-9a6f-7ab7281c7065",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.1.0-tuxcare.5 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ba3e0c7b-4580-54d0-ae16-4979e436cc1e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 17.1.0-tuxcare.5 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5adef789-aa52-5805-ac95-09d5c1ef4300",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.1.0-tuxcare.5 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:732527d7-35cd-52d4-a3d2-de4c00856659",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.1.0-tuxcare.5 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0ad8bc01-9a95-5cd6-99a6-b4eee1c6aeac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.1.0-tuxcare.5 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b49e75e8-43e6-50b1-8cfa-4be2be1f7e21",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.1.0-tuxcare.5 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:63d26a13-28be-5445-b3dc-fa1b023a9a23",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.1.0-tuxcare.5 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:462ca8a3-66c0-5a40-9ca2-fdaa5bcbc950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.1.0-tuxcare.5 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a0bba98c-46d9-57c4-9ac4-5746e4fcbae3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.1.0-tuxcare.5 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:bda0dc4d-a8d2-5441-abc3-0236315ee40a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.1.0-tuxcare.5 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:26854841-3910-59d7-9b4e-dd000b706429",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.1.0-tuxcare.5 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ad17b647-513f-5d27-8615-d9c94f6350aa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.1.0-tuxcare.5 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d25dd336-2ef8-5164-9f1a-7d79243eba82",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.1.0-tuxcare.5 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:67993d02-8d11-503e-975a-dc1e2152eb2e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 17.1.0-tuxcare.5 of @angular/forms. not_affected \u2014 Angular v17.1.0 does not have the TwoWayProperty IR operation that is the subject of CVE-2026-54265. Two-way bindings are desugared into separate property and event bindings before template pipeline processing, with the property half using the same parsePropertyBinding() code path as one-way property bindings, which are properly sanitized.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:fa0a26c0-35a9-5344-8e0c-72862a073786",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.1.0-tuxcare.5 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d96bbccd-857f-59c7-beb6-9b354628a42e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.1.0-tuxcare.5 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ac118139-f6df-5ebc-bc89-092e77666c70",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.1.0-tuxcare.5 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7fc5cc44-12fe-543c-9cd5-f5d175314f09",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 17.1.0-tuxcare.5 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:00ef11b0-03ff-5b95-92f5-5e7557c6e8e8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 17.1.0-tuxcare.5 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c8ca05af-110d-5b98-942d-a5226bdb8d99",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 17.1.0-tuxcare.5 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7db7125e-6308-5e3f-b72c-5c7f1316eb1c",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.1.0-tuxcare.5 of @angular/forms. not_affected \u2014 Angular 17.1.0 was never vulnerable to CVE-2026-88056. The vulnerability exists only in newer Angular versions (v18+, v19+, v20+ before fixes) where a url.ts file with a parseUrl function that uses String.prototype.trim() was introduced. Angular 17.1.0 does not have this file in the upstream release. TuxCare created url.ts for their 17.1.0 fork (commit e06d36f339 by ejarocki@cloudlinux.com) but...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b2f618a3-6d1a-5dde-8191-aca403fee753",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 17.1.0-tuxcare.5 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:687a8132-de71-5a04-91d5-ba5bd3b64347",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 17.1.0-tuxcare.5 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b6af9fe7-b5d5-5b2f-a5d0-a49769351c13",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 17.1.0-tuxcare.5 of @angular/forms."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.5"
    }
  ]
}