{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:22885a38-c01f-5a58-9126-5076404c7a9e",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/common",
      "purl": "pkg:npm/%40angular/common@6.1.10-tuxcare.13",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13",
      "version": "6.1.10-tuxcare.13",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:d21ec9c0-ae66-5f2e-a32b-989c91ae7a8f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 6.1.10-tuxcare.13 of @angular/common."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:39ccfd2f-826f-53f5-babc-af17a274e7a2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 6.1.10-tuxcare.13 of @angular/common."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:d6a1ebae-8ad3-58ab-8113-99cfb7ce0086",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 6.1.10-tuxcare.13 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:47777a33-f17e-5ac6-ab9a-c8bcbe8e7860",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-101895 does not affect version 6.1.10-tuxcare.13 of @angular/common. not_affected \u2014 CVE-2026-101895 describes a DoS vulnerability in domino's HTML parser (lib/HTMLParser.js), which is used by @angular/platform-server for SSR. However, the vulnerable code does NOT exist in this Angular repository - domino is only a declared dependency (package.json: \"domino\": \"2.0.1\"), not vendored source. The vulnerability would manifest in the installed node_modules after npm install, but the...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:2927ab52-f569-5014-a362-7e74c46c1561",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 6.1.10-tuxcare.13 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:2a869e43-dc98-54f4-a6d2-c7f6eca83354",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 6.1.10-tuxcare.13 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:5810ff83-55ab-50aa-aff9-c968f2447cee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 6.1.10-tuxcare.13 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:7dc9729f-cc4e-590a-be29-899ea72e6e20",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 6.1.10-tuxcare.13 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:2346d441-b1ed-5cb9-9e7d-2fb32e18734b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 6.1.10-tuxcare.13 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:268991db-a978-5267-aff5-4b51a2fe043b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 6.1.10-tuxcare.13 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:8add4ff3-b3bc-519b-b4f6-e492e3c78e6d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 6.1.10-tuxcare.13 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:f2503ae8-d776-56a0-aafd-b1348598ac07",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 6.1.10-tuxcare.13 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:c6f989af-65d1-5e77-8ba6-d18400c88a96",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 6.1.10-tuxcare.13 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:d36f8cd5-2dac-53f9-b977-890f7abc5873",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 6.1.10-tuxcare.13 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:c95637d9-8ed0-58cc-96af-45b8c65f24a0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 6.1.10-tuxcare.13 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:7d1a6d8b-7de0-5553-aa85-4e9ed0dfd587",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 6.1.10-tuxcare.13 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:50fb4f00-6035-5961-8dce-684cab714d48",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 6.1.10-tuxcare.13 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:ad666929-b754-5b02-ad5d-26c2645894de",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 6.1.10-tuxcare.13 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:a0db26db-98cf-5cb2-84fc-4dd8b05f150b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 6.1.10-tuxcare.13 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:7d077b75-0511-5720-bd88-d44d60d89a0c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 6.1.10-tuxcare.13 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:a9329815-da70-55d9-b4c6-b3ae0f8cd923",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 6.1.10-tuxcare.13 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:56b72c1e-a608-5f6a-a99a-7477825ccb5e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 6.1.10-tuxcare.13 of @angular/common. not_affected \u2014 Angular 6.1.10 is NOT AFFECTED by CVE-2026-68945. The vulnerable HttpTransferCache feature does not exist in this version \u2014 it was introduced in Angular 16.0.0 (April 2023), more than 5 years after Angular 6.1.10 (2018). The vulnerable file `packages/common/http/src/transfer_cache.ts` and all related APIs (`provideClientHydration`, `withNoHttpTransferCache`, `sortAndConcatParams`) are completel...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:c5c23f9a-bf89-58dc-b21c-f933a9981c2c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 6.1.10-tuxcare.13 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:f753e05e-7f20-58c2-b0e9-b397aa13bcdf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 6.1.10-tuxcare.13 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:79685e3e-e8aa-5467-accf-a1c83e5cff95",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 6.1.10-tuxcare.13 of @angular/common. not_affected \u2014 Angular version 6.1.10 is not affected by CVE-2026-88056. The vulnerable code pattern (url.ts with parseUrl using String.prototype.trim() and relativeUrlsTransformerInterceptorFn interceptor) does not exist in this version. These components were introduced in later Angular versions (post-6.1.10) and subsequently fixed in August 2026. Version 6.1.10 predates the vulnerable SSR URL resolution arc...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:61dc78b6-5ac4-50ea-889a-3e54aa06f1ec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 6.1.10-tuxcare.13 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:2fbdd54b-e88c-5683-b3a3-d961721968b8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 6.1.10-tuxcare.13 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:91c2a967-8785-5ffb-a566-0b0269ffc1d0",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 6.1.10-tuxcare.13 of @angular/common. not_affected \u2014 Angular 6.1.10 is not affected by CVE-2026-88059. The vulnerable HttpTransferCache feature, withRequestsMadeViaParent() delegation API, and modern hydration system (provideClientHydration()) do not exist in this version. These components were introduced in Angular 16+ (circa 2023), while the target version is from Angular 6 (2018). The vulnerability requires automatic HTTP response caching duri...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:082264a2-e831-5761-ab20-a9c9ad47b633",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 6.1.10-tuxcare.13 of @angular/common."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/common@6.1.10-tuxcare.13"
    }
  ]
}