{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:00a1197c-e6a7-5c3a-8743-19af08c02119",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/common",
      "purl": "pkg:npm/%40angular/common@17.1.0-tuxcare.6",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6",
      "version": "17.1.0-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d584179c-9f41-5755-abd3-699a8af6758d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.1.0-tuxcare.6 of @angular/common."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:202d2739-869a-5adb-8f4e-90ca73e4686f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.1.0-tuxcare.6 of @angular/common."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a1ff8d30-48cb-59ca-90b0-9d684d67fa53",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.1.0-tuxcare.6 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:681bccf0-7b0b-5d4b-a738-1d68ada40b94",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 17.1.0-tuxcare.6 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:972d3ce6-58c6-55e4-98dc-516dec4f9d17",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.1.0-tuxcare.6 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6124c4f1-5ef4-54c6-90e4-ff56f5d33e3b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.1.0-tuxcare.6 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:66e8f6d5-ccf6-5577-9346-f4084cfa3133",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.1.0-tuxcare.6 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ac6ed6f0-2c6c-51e1-b2ac-44a5d5d93f70",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 17.1.0-tuxcare.6 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f357f501-e030-5e81-be5c-51f17d93632a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.1.0-tuxcare.6 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b1e16db1-c0c0-5930-b8d5-c4e39e9efaf9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.1.0-tuxcare.6 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:794eaee4-0183-574f-94a6-d3badfe65211",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.1.0-tuxcare.6 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:119eba04-11fc-5ab8-a220-23bc68984f2e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.1.0-tuxcare.6 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:95c4338d-dfad-59ce-b221-36df2f1534b1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.1.0-tuxcare.6 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:506a3d7a-cbfc-5441-9200-a52b046514e2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.1.0-tuxcare.6 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7893cc53-1983-579b-bcb5-216edd66355b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.1.0-tuxcare.6 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9bf57878-2b60-5e72-b43c-f13791182fa1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.1.0-tuxcare.6 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ada775de-9183-54b4-84f3-79ebe6ee4b91",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.1.0-tuxcare.6 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:312d19a4-48bd-5236-af0d-813539cd5e52",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.1.0-tuxcare.6 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0e63ffda-6615-554d-be34-a284c8b8306b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.1.0-tuxcare.6 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:605a9975-86c6-521c-8603-57f5880273e3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 17.1.0-tuxcare.6 of @angular/common. not_affected \u2014 Angular v17.1.0 does not have the TwoWayProperty IR operation that is the subject of CVE-2026-54265. Two-way bindings are desugared into separate property and event bindings before template pipeline processing, with the property half using the same parsePropertyBinding() code path as one-way property bindings, which are properly sanitized.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9f3bc503-f381-5c2e-a74b-7f017966d207",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.1.0-tuxcare.6 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:692d3db0-8c1c-57dc-bbd2-1a3179f1d7b5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.1.0-tuxcare.6 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7d723838-2902-58ef-a5fe-cd5d7bfc2977",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.1.0-tuxcare.6 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3ebc4f17-7e8c-5317-a425-64ec24277f83",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 17.1.0-tuxcare.6 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a9581321-0f8a-52a7-bf34-582280ad303f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 17.1.0-tuxcare.6 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:96b137c7-d2c7-5037-a362-b9a2e7bf574d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 17.1.0-tuxcare.6 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7da7af6a-68f3-527e-bc84-bc02d7e41043",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.1.0-tuxcare.6 of @angular/common. not_affected \u2014 Angular 17.1.0 was never vulnerable to CVE-2026-88056. The vulnerability exists only in newer Angular versions (v18+, v19+, v20+ before fixes) where a url.ts file with a parseUrl function that uses String.prototype.trim() was introduced. Angular 17.1.0 does not have this file in the upstream release. TuxCare created url.ts for their 17.1.0 fork (commit e06d36f339 by ejarocki@cloudlinux.com) but...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a43e4454-d6ce-58c9-b73a-16a7ab3d69d8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 17.1.0-tuxcare.6 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ecd3c3f5-c1a6-579d-889b-6be9e0927b97",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88058 does not affect version 17.1.0-tuxcare.6 of @angular/common. not_affected \u2014 The Angular repository (version 17.1.0-tuxcare.5 at SHA 1b802ce320) is not affected by CVE-2026-88058 because it does not contain the vulnerable source code. The vulnerability exists in the domino library's HTML serialization code (lib/NodeUtils.js), which Angular references as a dependency in package.json but does not vendor. The upstream patch (89b20568dfaee1ec8e0b3bcf1872acdddd2f4fef) is a D...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9634a315-da03-5dbf-abf9-dc99d3b929e1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 17.1.0-tuxcare.6 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:fec5577a-b12e-5920-8477-f1eecff054c8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 17.1.0-tuxcare.6 of @angular/common."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/common@17.1.0-tuxcare.6"
    }
  ]
}