{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0e5fa095-a81d-58ca-b2ee-8ed231f25e30",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/language-service",
      "purl": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8",
      "version": "17.3.12-tuxcare.8",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:a6d4a3c5-b0c8-578f-b90a-cbd2f0edaf44",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.3.12-tuxcare.8 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:a02a7df2-8651-596d-aec6-56f84ccaa997",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.3.12-tuxcare.8 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:360fe273-ed23-599b-9bd6-cf1c7be07e59",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.3.12-tuxcare.8 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:9ada56b6-b9d0-5a85-8751-d2a5ec120021",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.3.12-tuxcare.8 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:048641ec-2da5-59f7-b90e-5a1e2becffad",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 17.3.12-tuxcare.8 of @angular/language-service, and is fixed in 17.3.12-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:7802cc54-7609-5c10-ac7d-3a6f816bd9f6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.3.12-tuxcare.8 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:8766a707-7906-5e7a-90cb-613150c66f46",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 17.3.12-tuxcare.8 of @angular/language-service, and is fixed in 17.3.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:bbb56111-5e4f-5e82-aa0e-78857f045fb8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 17.3.12-tuxcare.8 of @angular/language-service, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f8ee6270-1d1e-50fa-ba41-1b7a30020b3b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 17.3.12-tuxcare.8 of @angular/language-service, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:d59a7275-0f44-5a56-a37d-cc9f353a2a7d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 17.3.12-tuxcare.8 of @angular/language-service, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:922ea219-dc74-5a3c-ac9d-60717a339dd0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 17.3.12-tuxcare.8 of @angular/language-service, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:0f43cb55-efb9-5d5b-9c57-3c797288f47d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 17.3.12-tuxcare.8 of @angular/language-service, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:437e18c3-84d9-5e7a-9ed0-597755c0bc77",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 17.3.12-tuxcare.8 of @angular/language-service, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:7da584e2-ff24-5a5b-a7e0-c317dbcb6343",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 17.3.12-tuxcare.8 of @angular/language-service, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:845ed34b-ce65-5822-881d-a3b3c9916386",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 17.3.12-tuxcare.8 of @angular/language-service, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:421b5c26-d027-51a2-927c-05badbd1c516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 17.3.12-tuxcare.8 of @angular/language-service, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:719050ca-d1ee-54bc-86b9-0b40f3e33fa0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 17.3.12-tuxcare.8 of @angular/language-service, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:edadbd53-7978-5662-bf8b-d72b2e13c010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 17.3.12-tuxcare.8 of @angular/language-service, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:422cd0f5-1364-5199-b74e-656fb224f6fd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 17.3.12-tuxcare.8 of @angular/language-service, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:cef3c0e7-ec57-57d6-ab35-de0364f73b3c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 17.3.12-tuxcare.8 of @angular/language-service, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:5fe5939c-1dd0-53db-98dd-08a5ba31b3d9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 17.3.12-tuxcare.8 of @angular/language-service, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:b27dd12b-48e4-5ab9-ba75-bc7553736a5a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 17.3.12-tuxcare.8 of @angular/language-service, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:7e4f0e1f-8819-5256-9f39-5596d1c2072d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 17.3.12-tuxcare.8 of @angular/language-service, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:d2cb9071-dc75-5715-ba05-13a06c00fbb2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 17.3.12-tuxcare.8 of @angular/language-service, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:47c8e345-bf24-555d-a53f-cc7fb36dbbb9",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.3.12-tuxcare.8 of @angular/language-service. not_affected \u2014 Version 17.3.12 is not affected by CVE-2026-88056. The vulnerability involves String.prototype.trim() being applied during URL resolution in Angular's platform-server, converting validated same-origin URLs with Unicode whitespace into cross-origin protocol-relative URLs, leading to SSRF. This vulnerable code pattern was introduced in newer Angular versions (v20+) and does not exist in version 1...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:89f78b04-6f85-5234-9234-ff62540bb82f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 17.3.12-tuxcare.8 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:ba61ae2e-d191-5980-91e5-02cfa83924c8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 17.3.12-tuxcare.8 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:67f78132-a7ef-5b4a-9f74-ed2407b2465d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 17.3.12-tuxcare.8 of @angular/language-service."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.8"
    }
  ]
}