{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1351e8f2-f71c-5b0f-a69d-707a33a5c14b",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/bazel",
      "purl": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6",
      "version": "17.1.0-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1432327e-3b5b-530b-92ba-a89a10a8569b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.1.0-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f4b19c9c-5b9f-502a-bbc8-5badb1f8225d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.1.0-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7bf72478-bd8d-5d5d-92fe-3df9d01f1e83",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.1.0-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:603019d7-7e2a-5c01-b960-57e051099716",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 17.1.0-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:455db8fe-c46c-51ca-b5a7-9b10014ee000",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.1.0-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:60c4b327-34be-5248-b8b7-c081673d327b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.1.0-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6b8007c2-b4b3-55fc-878d-8e2c7935227a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.1.0-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c4cce4c7-4616-5b99-94aa-bea930748523",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 17.1.0-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e8b6eb90-2572-5129-912d-52e8303a1ba9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.1.0-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7de7c1c3-d4c3-53a5-bf6a-c6df7ef7332d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.1.0-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6b3599fc-eb08-5be4-ad28-428c429a1467",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.1.0-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6f9de754-07cf-5e10-9c43-4b1d414fd041",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.1.0-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:932e7ca3-5ea1-592b-a2e2-88b6e3333a62",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.1.0-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6a0b0687-4ced-5505-9666-13ebf1f05a27",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.1.0-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5bdaa670-b496-56e6-bbea-409ed32bf0ec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.1.0-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f0c06dc2-bea8-5ebc-bbbe-3ff5ec3c5e11",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.1.0-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d8310b74-2b66-59c5-9084-b0cb563a557f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.1.0-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6aa01988-ccd2-5984-ba1b-de3ce18c075b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.1.0-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1943c2ac-a389-50af-8e19-0a3288cb9cb0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.1.0-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e02a342f-9a8e-5c41-b9fc-8d23c9f80e44",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 17.1.0-tuxcare.6 of @angular/bazel. not_affected \u2014 Angular v17.1.0 does not have the TwoWayProperty IR operation that is the subject of CVE-2026-54265. Two-way bindings are desugared into separate property and event bindings before template pipeline processing, with the property half using the same parsePropertyBinding() code path as one-way property bindings, which are properly sanitized.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c6265e1e-bc9d-5c38-8d5b-079fad4092f9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.1.0-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c7a582eb-e4df-5478-99a6-08b6a8d10c75",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.1.0-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:53c0eef8-f589-51e4-bee0-2b4b5f56b1d9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.1.0-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:50700498-0356-5fd1-ace0-b836b98f5ffb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 17.1.0-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:086cb53c-61a1-50b3-a039-d71e4ed18c2c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 17.1.0-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:14e0f651-dcfd-518f-b1bd-21996552e394",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 17.1.0-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6b9a57dc-ec17-54b6-9141-a4042f23c770",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.1.0-tuxcare.6 of @angular/bazel. not_affected \u2014 Angular 17.1.0 was never vulnerable to CVE-2026-88056. The vulnerability exists only in newer Angular versions (v18+, v19+, v20+ before fixes) where a url.ts file with a parseUrl function that uses String.prototype.trim() was introduced. Angular 17.1.0 does not have this file in the upstream release. TuxCare created url.ts for their 17.1.0 fork (commit e06d36f339 by ejarocki@cloudlinux.com) but...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2c0d3d77-512f-5df4-af58-efd9665ffc2a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 17.1.0-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a7df7fab-43a1-5f78-ae07-05b3ddc8e0e9",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88058 does not affect version 17.1.0-tuxcare.6 of @angular/bazel. not_affected \u2014 The Angular repository (version 17.1.0-tuxcare.5 at SHA 1b802ce320) is not affected by CVE-2026-88058 because it does not contain the vulnerable source code. The vulnerability exists in the domino library's HTML serialization code (lib/NodeUtils.js), which Angular references as a dependency in package.json but does not vendor. The upstream patch (89b20568dfaee1ec8e0b3bcf1872acdddd2f4fef) is a D...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6b09c374-f3d1-57c1-be08-94e3ed066b7b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 17.1.0-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1d06b640-c77c-58ca-acb0-8061b87bf96e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 17.1.0-tuxcare.6 of @angular/bazel."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.6"
    }
  ]
}