{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f69a5c61-a54a-54f4-a98d-79a59cfa1b10",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/animations",
      "purl": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6",
      "version": "17.1.0-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:45ad0238-f05a-578a-8264-6141266a18b4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.1.0-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d65b3a2e-069d-53b7-b209-02ab3edefa46",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.1.0-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7ff79ed1-49ff-56dc-8857-b35b5ec1b8ea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.1.0-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:fa9d4ee4-cd40-5b28-bb51-c5eba3d9f3d6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 17.1.0-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6195860d-394c-58b4-a1ad-b5adb137a10e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.1.0-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:13f7a712-df85-5722-a6aa-f2e8f53c7af6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.1.0-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d2fdefa9-b762-585e-8474-f37d336183b8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.1.0-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e8ea4d44-9e42-5121-8e6f-a164691f69d2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 17.1.0-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c8e88be6-1ee2-5202-a81b-fe39c7688570",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.1.0-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a81cbf96-ce19-5bec-b01e-e88ab1fd8aba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.1.0-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:76f4e311-e274-551b-abd7-0a29ba415e2d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.1.0-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0dc09ec1-5c02-5c22-bc21-28b450ccb767",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.1.0-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e93c482c-5b9b-5f8d-aac3-c4368c8d0b84",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.1.0-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:93e0af41-7e6d-5c4c-91ee-1fd3be2d0d24",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.1.0-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:559e5a9b-efec-5bae-904a-0fc8ecdf44d2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.1.0-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0c561dc0-bf70-5ea0-aa5b-7b38902c356f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.1.0-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a5554b13-0592-5d8d-9ba3-3694555d3cdf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.1.0-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1144c45a-fc64-59ac-8d9d-211e1e4edcd7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.1.0-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0aa4ec50-370d-5cdd-a791-6f2e3bb3c4ce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.1.0-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:acaf7844-4dbc-5eff-b5ec-f034b4c58e50",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 17.1.0-tuxcare.6 of @angular/animations. not_affected \u2014 Angular v17.1.0 does not have the TwoWayProperty IR operation that is the subject of CVE-2026-54265. Two-way bindings are desugared into separate property and event bindings before template pipeline processing, with the property half using the same parsePropertyBinding() code path as one-way property bindings, which are properly sanitized.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:659e14a5-47c8-56fd-9161-beb79e3b6973",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.1.0-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:092d1abf-2370-5121-bdb7-d4a459020650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.1.0-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e252a403-a43d-5072-9030-ccfbc870667c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.1.0-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:cc141bec-a6dd-50b7-aceb-314ba41dc1fa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 17.1.0-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c88ecd28-5b3d-588d-9c32-dbb4fb8d0673",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 17.1.0-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1e6e029d-ccce-523f-b6e1-54069d4c6fba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 17.1.0-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:460fdc20-17df-5ca5-8e2e-e94a74657ade",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.1.0-tuxcare.6 of @angular/animations. not_affected \u2014 Angular 17.1.0 was never vulnerable to CVE-2026-88056. The vulnerability exists only in newer Angular versions (v18+, v19+, v20+ before fixes) where a url.ts file with a parseUrl function that uses String.prototype.trim() was introduced. Angular 17.1.0 does not have this file in the upstream release. TuxCare created url.ts for their 17.1.0 fork (commit e06d36f339 by ejarocki@cloudlinux.com) but...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:319f1b57-75c9-51cb-bc5c-98dadafdf0d2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 17.1.0-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:82766ae9-042e-5aa0-8091-4f3e7a85495e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88058 does not affect version 17.1.0-tuxcare.6 of @angular/animations. not_affected \u2014 The Angular repository (version 17.1.0-tuxcare.5 at SHA 1b802ce320) is not affected by CVE-2026-88058 because it does not contain the vulnerable source code. The vulnerability exists in the domino library's HTML serialization code (lib/NodeUtils.js), which Angular references as a dependency in package.json but does not vendor. The upstream patch (89b20568dfaee1ec8e0b3bcf1872acdddd2f4fef) is a D...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1fe91db2-1b57-5ae7-b1b7-3cd473be6a1b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 17.1.0-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2260541d-64d1-5644-b8ac-761017270066",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 17.1.0-tuxcare.6 of @angular/animations."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.6"
    }
  ]
}