{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7e5b7dcb-88db-5ea5-a0ca-40f701e71d8c",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/benchpress",
      "purl": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11",
      "version": "12.2.17-tuxcare.11",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:75ddeefe-527a-5cea-963f-ed9e02e05d62",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 12.2.17-tuxcare.11 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:6993b694-23ce-5a0b-aae1-53278ec69c0d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 12.2.17-tuxcare.11 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:1893f264-d3ee-52e1-b2a5-c7e14304aaaa",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-101895 does not affect version 12.2.17-tuxcare.11 of @angular/benchpress. not_affected \u2014 CVE-2026-101895 affects the domino HTML parser (lib/HTMLParser.js), not Angular's source code. The Angular framework repository declares domino as a dependency (package.json: \"domino\": \"^2.1.2\", yarn.lock: version 2.1.6), but does not vendor or bundle domino's source code. Exhaustive search confirms no HTMLParser.js or after_doctype_name_state code exists in the Angular repository. While Angula...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:7efc3c21-c534-51ca-9d17-47c2e4286f25",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 12.2.17-tuxcare.11 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:e6ad21fc-97cd-5b48-a156-1d959d1ebd36",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 12.2.17-tuxcare.11 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:c0bba327-c012-55da-ab4f-02284ac05f18",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 12.2.17-tuxcare.11 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:75235959-24fc-58c3-a939-61f3ab8b46ed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 12.2.17-tuxcare.11 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:efe6e49c-333e-5505-ae7f-656d6f3e013f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 12.2.17-tuxcare.11 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:363fe34c-2002-51f4-8750-0d254ef12fea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 12.2.17-tuxcare.11 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:a563bc18-5233-5d44-84e0-0122e57f2934",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 12.2.17-tuxcare.11 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:a9c5822a-ed59-58c5-b659-c41f9115e10b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 12.2.17-tuxcare.11 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:39893df4-7a05-578e-8792-cb7bd8adabb2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 12.2.17-tuxcare.11 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:ed73c283-640c-52f4-940a-e80eeb085dd3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 12.2.17-tuxcare.11 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:c1a0af0c-85a2-5456-bb9a-8cde378ff6ae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 12.2.17-tuxcare.11 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:e4cc064b-850f-5c68-898d-a350adaf5a61",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 12.2.17-tuxcare.11 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:0c11230a-6c12-5055-9c03-b5ab35c60cbc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 12.2.17-tuxcare.11 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:94966820-285a-5b82-b766-f221b9bf8c06",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 12.2.17-tuxcare.11 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:cd917d4c-f52d-55f0-9f19-4da13ae1ca7b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 12.2.17-tuxcare.11 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:c32f91e8-3079-5858-b9a8-3074f6f856b9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 12.2.17-tuxcare.11 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:2b73e5cd-03bc-50cf-a2ba-9b02906b408c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 12.2.17-tuxcare.11 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:67fe8dbb-7516-5519-a2b1-82e8299be30b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 12.2.17-tuxcare.11 of @angular/benchpress. not_affected \u2014 Angular 12.2.17 does not contain the HttpTransferCache feature affected by CVE-2026-68945. HttpTransferCache, which caches HTTP requests during Server-Side Rendering (SSR), was first introduced in Angular 16.0.0\u2014approximately 4 major versions after the target version. The vulnerability concerns cache-key collision when repeated HTTP parameters are serialized, but since the entire HttpTransferCa...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:b608b3cf-cd48-52bf-b095-956d184d1276",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 12.2.17-tuxcare.11 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:edf06bf5-d01d-5f56-bbc6-4349faa1f7d5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 12.2.17-tuxcare.11 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:963157bd-8807-5370-ae61-4589025193c0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88056 is fixed in version 12.2.17-tuxcare.11 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:916de901-e954-57f0-93d9-64c3909ca359",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 12.2.17-tuxcare.11 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:e96c94a0-db2f-5776-834e-065f5219b0c7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 12.2.17-tuxcare.11 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:f83dad48-c0a0-54aa-893c-8c285f18cc71",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 12.2.17-tuxcare.11 of @angular/benchpress. not_affected \u2014 Angular 12.2.17-tuxcare.9 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, withRequestsMadeViaParent(), and provideClientHydration() features which were introduced in Angular 16.0.0. This version uses the older module-based HttpClientModule system and lacks the entire SSR hydration transfer-cache infrastructure. The vulnerable code pattern described in the CVE do...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:77e1f40a-af79-5be4-89f7-5846f7e28275",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 12.2.17-tuxcare.11 of @angular/benchpress."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/benchpress@12.2.17-tuxcare.11"
    }
  ]
}