{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5a851b6c-0258-5ae9-9e73-d2589f3630d3",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/common",
      "purl": "pkg:npm/%40angular/common@17.3.12-tuxcare.16",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16",
      "version": "17.3.12-tuxcare.16",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:3388bdfb-ace6-59fa-bafa-70d965a3c5be",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.3.12-tuxcare.16 of @angular/common."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:26113c9b-2bb5-5d4e-a24a-04d2f49fbd3b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.3.12-tuxcare.16 of @angular/common."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:f8f88468-add7-5ed6-ab35-f556f1999bc5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.3.12-tuxcare.16 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:1f18ad55-2e4e-58f8-9af3-b521a0b2e8c1",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-101895 does not affect version 17.3.12-tuxcare.16 of @angular/common. not_affected \u2014 The vulnerable code (domino's lib/HTMLParser.js with the after_doctype_name_state infinite loop bug) is NOT present in this Angular source repository. Domino exists only as a declared npm dependency in package.json (line 110: \"domino\": \"https://github.com/angular/domino.git#8f228f8862540c6ccd14f76b5a1d9bb5458618af\"). The BUILD.bazel shows domino is bundled at build time from @npm//:node_modules...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:df31eaa6-d2dd-5143-80e3-79634a7063d3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.3.12-tuxcare.16 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:9817aecc-f2cc-5a89-b786-42fe37e0aafc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.3.12-tuxcare.16 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:58c84688-ddf9-5212-bd7b-5181ff81cc58",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.3.12-tuxcare.16 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:266173ba-a707-57bc-9e51-d66678b5bbe7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.3.12-tuxcare.16 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:5c589483-7929-5df3-a82f-7d55aad97bcc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.3.12-tuxcare.16 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:420f6804-c2a5-5b75-b5d6-fdf1f2ac23e6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.3.12-tuxcare.16 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:c152cf66-303e-5f6e-b903-0627c28dac6a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.3.12-tuxcare.16 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:33e50dc1-e2b2-5ed9-8203-bbee476b5fd0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.3.12-tuxcare.16 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:3320bc95-696d-5e77-9786-6767cf323009",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.3.12-tuxcare.16 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:a204606b-90f5-57ae-9b92-ed28a9a2d4fd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.3.12-tuxcare.16 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:b14bab32-4344-5c64-bb88-cfded00cb2f3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.3.12-tuxcare.16 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:ccdfd10e-6ca9-5ffd-8093-96bf3ba2edcb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.3.12-tuxcare.16 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:eaca57c2-d85c-5bed-93d6-f4c191485a10",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.3.12-tuxcare.16 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:2f235a5a-889d-56b0-91ef-dd8df40ed75f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.3.12-tuxcare.16 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:45e97e9c-8c9b-501e-a117-afc52442b8a8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 17.3.12-tuxcare.16 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:1b67e1e3-fd9b-540f-bdc6-4c91e72d7df6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.3.12-tuxcare.16 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:da8ab5dc-0d31-54e5-9942-4f58ef6aa70a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.3.12-tuxcare.16 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:0d1292a4-f411-5aed-9697-915b75ba3bf0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.3.12-tuxcare.16 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:fc0a6997-31a5-5ccd-bd30-761d1279cfd4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 17.3.12-tuxcare.16 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:f3086751-f6b1-59f4-9394-f2edd3716c7f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 17.3.12-tuxcare.16 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:5c3cea6a-dc99-5967-bf92-8f66acbd657e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 17.3.12-tuxcare.16 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:ab8c44a5-a597-5033-848f-92c7cffb732d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.3.12-tuxcare.16 of @angular/common. not_affected \u2014 Version 17.3.12 is not affected by CVE-2026-88056. The vulnerability involves String.prototype.trim() being applied during URL resolution in Angular's platform-server, converting validated same-origin URLs with Unicode whitespace into cross-origin protocol-relative URLs, leading to SSRF. This vulnerable code pattern was introduced in newer Angular versions (v20+) and does not exist in version 1...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:7571fcce-e42f-554e-ad9b-c3d7e9ba563f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 17.3.12-tuxcare.16 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:dd831c59-830b-5554-93c2-ff389402b697",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 17.3.12-tuxcare.16 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:ae5cac09-85a9-516c-82ea-cd531a8fb888",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 17.3.12-tuxcare.16 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:ca066a32-27c7-5f60-a4b7-22fc8b08bdfb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 17.3.12-tuxcare.16 of @angular/common."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/common@17.3.12-tuxcare.16"
    }
  ]
}