{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fd2964db-af31-5f98-81a2-f6e34e18f2a8",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/core",
      "purl": "pkg:npm/%40angular/core@18.1.2-tuxcare.6",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6",
      "version": "18.1.2-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:06fb35f0-6d62-5e45-8ba8-6a9fe694e242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 18.1.2-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:40072358-d0fd-5dcf-aa04-ed779fa2e288",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.1.2-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:95f97d91-dae6-5b38-aa4d-7fc108675990",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.1.2-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d5ce87b4-5618-5ff0-b5a0-03a6579fee89",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-101895 does not affect version 18.1.2-tuxcare.6 of @angular/core. not_affected \u2014 The Angular repository (v18.1.2-tuxcare.6) does not contain the vulnerable code for CVE-2026-101895. The DoS vulnerability exists in domino's HTMLParser.js (after_doctype_name_state infinite loop), but domino is an external npm dependency whose source code is not vendored or bundled in this repository. While Angular's platform-server does call domino.createWindow(html) and exposes the vulnerabi...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:325e609e-9710-59f6-bdff-098e42fc574a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.1.2-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:73267401-f051-5651-baf5-bc4fca028de5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.1.2-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:11e2675d-1992-56cc-94c5-99390211d792",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.1.2-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:34a84dd6-5584-52a4-9785-6a33a7455d2f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 18.1.2-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:97db769c-0626-5729-a01e-4e1ce7a4a076",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 18.1.2-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6ad29cad-4f11-5803-b372-d8a74ea68e39",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 18.1.2-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c91b4fd0-0b6f-58c3-8ac0-0645eda16cd0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 18.1.2-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:601288a9-ccc5-574c-8927-e0cd599bc682",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 18.1.2-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d75955d9-44e1-5b3c-89d7-3a5d996cb172",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 18.1.2-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a70bfb3e-4f6c-593e-83b7-0cb82a983016",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 18.1.2-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6c4fe6cb-b912-572e-b193-eb59e68461e1",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50555 does not affect version 18.1.2-tuxcare.6 of @angular/core. already_fixed \u2014 The target Angular 18.1.2 repository has already been patched for this vulnerability. TuxCare commit 32991dd728 'fix all CVEs' added a cumulative domino patch that fixes both the NOSCRIPT XSS vulnerability (CVE-2026-50556, corresponding to the provided patch f74cccd) and the astral Unicode index bug (CVE-2026-50555). The patch is applied automatically to the domino dependency via patch-package ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c73a503b-0a05-5323-8b3c-bdfa21aa168d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50556 does not affect version 18.1.2-tuxcare.6 of @angular/core. already_fixed \u2014 CVE-2026-50556 (XSS via noscript raw-text serialization in domino) has been fixed in this Angular repository. The fix is present in tools/esm-interop/patches/npm/domino+2.1.6.patch and is automatically applied to the domino dependency during installation via the postinstall script. The patch was added by TuxCare in commit 32991dd728 on 2026-07-01.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:33deec76-8b3c-5cb4-8c32-736ebb26b95c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 18.1.2-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b2c1260c-6179-5819-9e16-5d730bf71b7b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 18.1.2-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2f72b2e6-62c2-5ef6-af15-66b67aabcbb7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 18.1.2-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:27aa9750-4a8f-5df3-b733-dba431780cbd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 18.1.2-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9a19cd0d-19dd-549c-9b8e-71ae24ada3a5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 18.1.2-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6eb4ffb2-9e05-5d1b-8475-b5c586e23fbc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 18.1.2-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9c1eec62-3fdc-5eaf-97fe-eae67625bbbe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 18.1.2-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:23e5d2c2-7698-5bb7-9659-4f307b123a59",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 18.1.2-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4f0a1a34-b642-5b1c-a454-a97efb50b72b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 18.1.2-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b931e9b5-6780-5ebb-887a-fb7081c96fd7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 18.1.2-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a3723f4d-e021-5f04-a8b1-c4cd1a0532ad",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.1.2-tuxcare.6 of @angular/core. not_affected \u2014 The target version (Angular 18.1.2) does NOT contain the vulnerable code pattern. CVE-2026-88056 describes a Unicode whitespace trimming vulnerability in Angular SSR's URL resolution, where `String.prototype.trim()` strips characters like U+00A0, converting same-origin paths into protocol-relative cross-origin URLs. The vulnerability was introduced in Angular v20.x during a refactoring (commit ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:bd4d9d54-79fa-51d0-b650-3659da5d547e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 18.1.2-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:20d2b79c-d951-501f-9f91-32c93b044230",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 18.1.2-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:85a4d397-d912-5a78-b6f3-f4ee36a163a6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 18.1.2-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4035073a-0e09-5d75-bcc4-8ec7311017b1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 18.1.2-tuxcare.6 of @angular/core."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/core@18.1.2-tuxcare.6"
    }
  ]
}