{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f3ec79e4-dd33-5d93-ba9d-b5433068c3a9",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/benchpress",
      "purl": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14",
      "version": "16.2.12-tuxcare.14",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:52fa2bdf-5a72-554d-8f65-4c03fb906c1f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 16.2.12-tuxcare.14 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:8e13aa77-f0a2-53f6-ae2a-e784e10c5f8f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.12-tuxcare.14 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:1a72086b-8b48-58a4-844e-0c330d4add04",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 16.2.12-tuxcare.14 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:3d9be486-6250-5855-96ef-dbe44a59fc8a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-101895 does not affect version 16.2.12-tuxcare.14 of @angular/benchpress. not_affected \u2014 The target repository (@angular/platform-server version 16.2.12-tuxcare.14) is not affected by CVE-2026-101895 because the vulnerable code pattern does not exist in this repository. The CVE describes an infinite loop in domino's lib/HTMLParser.js (specifically in after_doctype_name_state when handling incomplete DOCTYPE declarations with EOF). Domino is referenced only as a declared dependency ...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:77a03dcd-d2e1-50cc-a4fc-6605614ae5a3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 16.2.12-tuxcare.14 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:ae43bbb8-9154-5b40-b890-135485695a56",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 16.2.12-tuxcare.14 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:e34edbc3-8c50-57d1-bef4-bf1e0aca4200",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 16.2.12-tuxcare.14 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:2655b348-d1fd-518d-a01e-d72e70268cc2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 16.2.12-tuxcare.14 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:37f2ef5b-5dff-5645-b260-c3877ed1e9cb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 16.2.12-tuxcare.14 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:8aa073b6-bb67-5724-ab37-cb0fe9e99e59",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 16.2.12-tuxcare.14 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:3095a6ea-13a2-5145-8cc6-f9e3c6c59ae0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 16.2.12-tuxcare.14 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:e0e7a6e9-d0fa-5fd3-ba32-4464960e1d46",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 16.2.12-tuxcare.14 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:38dec3a5-1ffb-5454-8e69-bcdda42d2297",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 16.2.12-tuxcare.14 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:91037f21-a3a9-5737-8e33-8719207944ac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 16.2.12-tuxcare.14 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:7742c72f-35c7-509e-8f80-b3fd3eb270f5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 16.2.12-tuxcare.14 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:bb97da03-c299-5e42-9ef1-856b1dd8101a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 16.2.12-tuxcare.14 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:4a2c2c95-19e6-5022-a039-2a810820d8a1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 16.2.12-tuxcare.14 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:b749576e-e4a6-5fd3-a3ce-66a1fe67e818",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 16.2.12-tuxcare.14 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:d4193273-747f-505f-90d1-7e67859108d1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 16.2.12-tuxcare.14 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:332b9a6c-16bb-54ab-8c7f-49cf7423b0cb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 16.2.12-tuxcare.14 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:aa28a6fd-c9f6-514b-b3bc-685315a037f6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 16.2.12-tuxcare.14 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:70d458ae-2a58-515e-a93c-25cab18a56ca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 16.2.12-tuxcare.14 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:dcc7c752-eff2-502f-99a5-29ef59b6c5a4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 16.2.12-tuxcare.14 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:e8abd57f-9014-5ffc-97ac-96d08fa5123f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 16.2.12-tuxcare.14 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:72a9d716-7da5-57dc-9df6-85ba8fbbbadd",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.12-tuxcare.14 of @angular/benchpress. not_affected \u2014 CVE-2026-88056 affects Angular versions 20.3.x, 21.2.x, and 22.x where a refactored URL parsing utility added String.prototype.trim() that strips Unicode whitespace, enabling SSRF bypasses. The target (Angular 16.2.12-tuxcare.12) is based on Angular 16.2.x architecture, which predates the vulnerable code pattern entirely. TuxCare created url.ts fresh on June 24, 2026 for CVE-2026-50168, modelin...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:ead4b305-25a5-59fa-9d6a-d90ab2e36f63",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 16.2.12-tuxcare.14 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:fd8d68e5-14b5-5937-ae13-247511d83f71",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 16.2.12-tuxcare.14 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:ee38f016-10cb-507a-bf17-7f0bfa079bb3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 16.2.12-tuxcare.14 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:ea76e2ff-eef5-53ef-8c11-c2c8869c00e2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 16.2.12-tuxcare.14 of @angular/benchpress."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.14"
    }
  ]
}