{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d84ef58f-35d9-5cf1-b882-5e05b419dc0a",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/core",
      "purl": "pkg:npm/%40angular/core@17.1.0-tuxcare.6",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6",
      "version": "17.1.0-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f3ebf2aa-109d-5480-8d25-226ea377d799",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.1.0-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d95499e0-b896-5ae0-a0aa-31cc1ebb5e46",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.1.0-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2bb09da8-dab1-54f8-85e8-2085fe515be3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.1.0-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:fcb35e15-7d39-561a-8ecd-956f98ab367e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 17.1.0-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:85f7fe7b-8ba5-56c4-8d6f-d590b828bbdf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.1.0-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:65f27a19-e9da-5438-afce-f3ffac5b4269",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.1.0-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8ef85994-186e-5078-8f49-39a9515eccd2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.1.0-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e98388aa-7a5d-5523-937a-a3350e3d4481",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 17.1.0-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ff7f61a0-9196-5af0-85d1-7d982be623f5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.1.0-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2d81b0c2-89bb-5769-a639-5bc2acc6ccd9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.1.0-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3624cf84-81c7-55c5-8043-17ffb082d26f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.1.0-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:67e83144-db3c-5aa3-85fd-4767b40796a2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.1.0-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:abdcaa7d-2476-5c80-ad89-f265e6284d11",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.1.0-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e2b083e7-5507-569d-bc4d-9a166a17a3d0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.1.0-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:edc681b4-116a-552f-8d4f-9af13485ebed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.1.0-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:24a1056c-004e-581f-b68f-dbe9c11921fe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.1.0-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:40868c6e-ce80-5b49-bfca-458dd06f8cb3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.1.0-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6722d94f-3ac9-523c-9613-2265d58e9da3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.1.0-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8127de15-9ba7-514a-98ae-7241a4b6e4aa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.1.0-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e9c85383-1385-511b-a63c-e5e9a54e0ead",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 17.1.0-tuxcare.6 of @angular/core. not_affected \u2014 Angular v17.1.0 does not have the TwoWayProperty IR operation that is the subject of CVE-2026-54265. Two-way bindings are desugared into separate property and event bindings before template pipeline processing, with the property half using the same parsePropertyBinding() code path as one-way property bindings, which are properly sanitized.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a37d29bb-f793-540f-b62f-e5a1dd167f7c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.1.0-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c2ad7f10-c7c8-5b31-8a4e-07aea047feba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.1.0-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b6408eff-298a-5ea0-827f-2ef2f94602b2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.1.0-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ed0a2290-9871-56f9-8917-16be3c21b4bc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 17.1.0-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:88e6d096-fbba-56c5-8587-bf66b32bb6b6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 17.1.0-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4d55d187-6768-537b-bfce-8644ccaa60d1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 17.1.0-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ec41f509-d94f-58e9-b621-5664a3320e33",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.1.0-tuxcare.6 of @angular/core. not_affected \u2014 Angular 17.1.0 was never vulnerable to CVE-2026-88056. The vulnerability exists only in newer Angular versions (v18+, v19+, v20+ before fixes) where a url.ts file with a parseUrl function that uses String.prototype.trim() was introduced. Angular 17.1.0 does not have this file in the upstream release. TuxCare created url.ts for their 17.1.0 fork (commit e06d36f339 by ejarocki@cloudlinux.com) but...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8261e136-e7b1-5ccd-ac06-d2dcb2fb41b9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 17.1.0-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2d1fb714-c2cd-59ea-9842-24e40bb35eed",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88058 does not affect version 17.1.0-tuxcare.6 of @angular/core. not_affected \u2014 The Angular repository (version 17.1.0-tuxcare.5 at SHA 1b802ce320) is not affected by CVE-2026-88058 because it does not contain the vulnerable source code. The vulnerability exists in the domino library's HTML serialization code (lib/NodeUtils.js), which Angular references as a dependency in package.json but does not vendor. The upstream patch (89b20568dfaee1ec8e0b3bcf1872acdddd2f4fef) is a D...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:cff0b317-94bb-5511-b1b1-0a1a60349d45",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 17.1.0-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:831d3aa1-ba9c-53d5-a2a8-e8a25d73a9fd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 17.1.0-tuxcare.6 of @angular/core."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.6"
    }
  ]
}