{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3461ea14-d914-5725-bd87-daacf772044e",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/forms",
      "purl": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14",
      "version": "16.2.12-tuxcare.14",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:3794fe89-aea4-57ee-a5db-2efd58fd32f1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 16.2.12-tuxcare.14 of @angular/forms."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:e6056e09-139c-554e-91dd-2bf1669d0f3d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.12-tuxcare.14 of @angular/forms."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:412586c8-fa70-53b2-960e-03d2e7adc03d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 16.2.12-tuxcare.14 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:ec47b558-22a7-52d7-b1a8-819ec3f97558",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-101895 does not affect version 16.2.12-tuxcare.14 of @angular/forms. not_affected \u2014 The target repository (@angular/platform-server version 16.2.12-tuxcare.14) is not affected by CVE-2026-101895 because the vulnerable code pattern does not exist in this repository. The CVE describes an infinite loop in domino's lib/HTMLParser.js (specifically in after_doctype_name_state when handling incomplete DOCTYPE declarations with EOF). Domino is referenced only as a declared dependency ...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:aa9b0acc-78bb-54e7-a6d9-ad2a590f30c4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 16.2.12-tuxcare.14 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:4761500e-90a3-535a-84fd-e559c8e41e74",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 16.2.12-tuxcare.14 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:a3700379-7adf-5dcf-84b9-41a41dbccc4e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 16.2.12-tuxcare.14 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:b9b56e48-afa1-5e6f-b9ad-2616ee2d3e6a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 16.2.12-tuxcare.14 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:a78b2d31-c8f1-5e98-8e20-4568ceb4f799",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 16.2.12-tuxcare.14 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:de9dfa05-35fa-55c4-a9a3-add54340db89",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 16.2.12-tuxcare.14 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:047050c5-eb23-5132-a685-5feb52165bb0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 16.2.12-tuxcare.14 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:29749c33-55b6-5e05-9019-31179e38152c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 16.2.12-tuxcare.14 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:6d27ebf8-641c-5455-8f82-7bec05da29a5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 16.2.12-tuxcare.14 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:81df31de-5751-552e-a4fd-5a7c7379fd84",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 16.2.12-tuxcare.14 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:0d2c1006-12a9-5f09-8ab5-94e9aa3c459a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 16.2.12-tuxcare.14 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:83d22699-4299-5600-aec0-92e67c4d4c84",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 16.2.12-tuxcare.14 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:35abd9d4-643f-56fd-b829-7ef960e7c885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 16.2.12-tuxcare.14 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:e3438280-2255-5a2f-9575-039a265f0f33",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 16.2.12-tuxcare.14 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:c7b8b514-91dc-532f-aca1-21804d43baee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 16.2.12-tuxcare.14 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:6ea48589-78aa-5a11-bddf-38dc1bbbc761",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 16.2.12-tuxcare.14 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:172872d6-e042-5240-a805-fbb0406e8d4c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 16.2.12-tuxcare.14 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:697dc40e-5c5d-5d4b-8770-1ac6be0a5654",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 16.2.12-tuxcare.14 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:6389395d-4069-5ea2-9d0c-b6b6761cb50f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 16.2.12-tuxcare.14 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:f05d24cd-176d-588b-a618-955d00bf838f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 16.2.12-tuxcare.14 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:c58f72d6-73a8-527a-ac04-4c3107702f05",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.12-tuxcare.14 of @angular/forms. not_affected \u2014 CVE-2026-88056 affects Angular versions 20.3.x, 21.2.x, and 22.x where a refactored URL parsing utility added String.prototype.trim() that strips Unicode whitespace, enabling SSRF bypasses. The target (Angular 16.2.12-tuxcare.12) is based on Angular 16.2.x architecture, which predates the vulnerable code pattern entirely. TuxCare created url.ts fresh on June 24, 2026 for CVE-2026-50168, modelin...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:f6ced50f-140e-5265-a8f7-8d067d69dd77",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 16.2.12-tuxcare.14 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:ad046bb7-6157-589c-9098-ffa9b32a5a26",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 16.2.12-tuxcare.14 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:1da18bb1-6f13-5a84-ab35-1df980ab3e05",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 16.2.12-tuxcare.14 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:68721e34-df9e-5ecd-bd8a-cbb360e5d84b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 16.2.12-tuxcare.14 of @angular/forms."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/forms@16.2.12-tuxcare.14"
    }
  ]
}