{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f3a2f150-940d-55f0-b658-966d44e58e17",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/compiler",
      "purl": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14",
      "version": "16.2.12-tuxcare.14",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:2f8a5e9b-fbf9-59e4-b9b9-f2ede364904d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 16.2.12-tuxcare.14 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:3f1cc4e8-93a9-58e4-8f3b-ec68f948b4bd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.12-tuxcare.14 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:59e40b5c-4f16-520e-9ae8-601e02cf420e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 16.2.12-tuxcare.14 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:4aefa192-2ec2-527b-987e-afc6cdbb1889",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-101895 does not affect version 16.2.12-tuxcare.14 of @angular/compiler. not_affected \u2014 The target repository (@angular/platform-server version 16.2.12-tuxcare.14) is not affected by CVE-2026-101895 because the vulnerable code pattern does not exist in this repository. The CVE describes an infinite loop in domino's lib/HTMLParser.js (specifically in after_doctype_name_state when handling incomplete DOCTYPE declarations with EOF). Domino is referenced only as a declared dependency ...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:6037fd8f-f49c-572b-9609-23bd0f731385",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 16.2.12-tuxcare.14 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:f5b57889-ff8a-5b3d-a4ac-bc1528df8de5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 16.2.12-tuxcare.14 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:b64d328e-19fd-52c1-8ff9-e3ae396920a6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 16.2.12-tuxcare.14 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:7a0359ba-1045-5b29-ac46-5eb99b62d1c4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 16.2.12-tuxcare.14 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:4409a3d5-db2c-5981-b0ae-b2551fc40c6b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 16.2.12-tuxcare.14 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:e25bc48a-5515-544f-9adc-433d9e9a26d9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 16.2.12-tuxcare.14 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:c6d490d7-51bf-5e72-92ad-69120ab92264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 16.2.12-tuxcare.14 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:dbeeba32-e39e-52f0-bb54-7fd5ef41354c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 16.2.12-tuxcare.14 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:7fdfe08c-25f4-55f3-b9b7-f89acaaa0e89",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 16.2.12-tuxcare.14 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:a8ed0492-d57c-5f42-bc1c-3d218a712b2c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 16.2.12-tuxcare.14 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:4b0e74ae-ff47-5756-a242-d16cfac4a6b6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 16.2.12-tuxcare.14 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:408df90f-6581-506a-9d17-63aecba662ad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 16.2.12-tuxcare.14 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:e1978c44-5428-5183-bcf5-f579ab518559",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 16.2.12-tuxcare.14 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:c50edbc8-5238-5e2a-a96b-3796c264bbb2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 16.2.12-tuxcare.14 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:a8b55f31-cc59-558a-973c-8a7db739a4ca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 16.2.12-tuxcare.14 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:f748186f-ec2c-5927-950a-45849bae95fe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 16.2.12-tuxcare.14 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:43ca4cc2-f827-525b-b96f-d7519f63ec96",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 16.2.12-tuxcare.14 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:da378dfd-4ec4-51b9-a8b0-65074451b9f6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 16.2.12-tuxcare.14 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:c49e8733-1173-5c70-8021-be6fde8c16bf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 16.2.12-tuxcare.14 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:24f1c741-359e-5426-8b18-c084fed8ac6b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 16.2.12-tuxcare.14 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:dceac446-929a-5799-8a82-483fff582acd",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.12-tuxcare.14 of @angular/compiler. not_affected \u2014 CVE-2026-88056 affects Angular versions 20.3.x, 21.2.x, and 22.x where a refactored URL parsing utility added String.prototype.trim() that strips Unicode whitespace, enabling SSRF bypasses. The target (Angular 16.2.12-tuxcare.12) is based on Angular 16.2.x architecture, which predates the vulnerable code pattern entirely. TuxCare created url.ts fresh on June 24, 2026 for CVE-2026-50168, modelin...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:5c45e71c-1ff6-53f3-b48e-e1207bb18415",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 16.2.12-tuxcare.14 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:79cc1235-45af-5c1c-af85-29009c612d54",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 16.2.12-tuxcare.14 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:19da59be-bbfc-5124-b1ed-755c9a4b0376",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 16.2.12-tuxcare.14 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:be2cc9f0-ddfc-5de3-802d-07960acb400b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 16.2.12-tuxcare.14 of @angular/compiler."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler@16.2.12-tuxcare.14"
    }
  ]
}