{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d1dcda74-aba3-562e-8a18-4f2317d95d60",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/forms",
      "purl": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6",
      "version": "17.1.0-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c0b4992f-93f1-5f7f-b14c-f9f94203b663",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.1.0-tuxcare.6 of @angular/forms."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d3a2b2b3-1896-5b9f-801e-ea3357b8e857",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.1.0-tuxcare.6 of @angular/forms."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a21d4987-1c9f-5e89-a11c-2c9b4e62b8fc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.1.0-tuxcare.6 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e5c25ff4-6984-5bca-bd30-ce91f78ac4a6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 17.1.0-tuxcare.6 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:24b557ff-3871-520b-a8ad-f7f8d5f02207",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.1.0-tuxcare.6 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e73160b0-dece-5fc4-bb2e-36efaf0e403e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.1.0-tuxcare.6 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:42be1dd5-6407-5616-8900-0cd6486d6551",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.1.0-tuxcare.6 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5c05d805-bbdf-518c-9098-fa086732e4cc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 17.1.0-tuxcare.6 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:753bfd1d-f057-5feb-aff2-20a8ee33f2b5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.1.0-tuxcare.6 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b5794385-5e23-5a5f-a0be-3904e787141f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.1.0-tuxcare.6 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:37d89eda-bc69-5a2c-b08c-cba726952963",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.1.0-tuxcare.6 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:eda2bb46-9005-54c0-9336-cc0ca374cb8c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.1.0-tuxcare.6 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:43bb1090-bbcd-5e92-b4b3-8d355dee849c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.1.0-tuxcare.6 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:705ea617-f616-59dd-b038-8a958ccb475a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.1.0-tuxcare.6 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e45adb94-f3ed-5528-9450-7d052d02e4eb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.1.0-tuxcare.6 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:789c4314-e941-5f7b-a105-806be8f61faf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.1.0-tuxcare.6 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b18a0a50-8f9c-56a2-8404-0382a1bbadfd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.1.0-tuxcare.6 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:368971a9-4a4a-5bb1-885b-2ccfb44ddf87",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.1.0-tuxcare.6 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4fe74ab9-ea18-5519-a39a-b68ee4a28b84",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.1.0-tuxcare.6 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6b84a9c3-2654-57c6-b8c3-6a8d0529a0a1",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 17.1.0-tuxcare.6 of @angular/forms. not_affected \u2014 Angular v17.1.0 does not have the TwoWayProperty IR operation that is the subject of CVE-2026-54265. Two-way bindings are desugared into separate property and event bindings before template pipeline processing, with the property half using the same parsePropertyBinding() code path as one-way property bindings, which are properly sanitized.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ac697c5f-f014-5537-984b-bc1ab2a5d830",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.1.0-tuxcare.6 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b842ec39-59de-5ca8-a6a7-aa0866d66ad3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.1.0-tuxcare.6 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a475bab0-5bbd-5b7f-b46b-2fdd10abe279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.1.0-tuxcare.6 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4d8bc711-540d-58a1-a766-7d3a772bc4d0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 17.1.0-tuxcare.6 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:df152bd9-5398-59c1-854b-5226f9abb51b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 17.1.0-tuxcare.6 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:87a7b93d-ef31-54df-8e3a-ef761a461d37",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 17.1.0-tuxcare.6 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:fcf653f6-ccb8-52f9-9999-c4b5ede80290",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.1.0-tuxcare.6 of @angular/forms. not_affected \u2014 Angular 17.1.0 was never vulnerable to CVE-2026-88056. The vulnerability exists only in newer Angular versions (v18+, v19+, v20+ before fixes) where a url.ts file with a parseUrl function that uses String.prototype.trim() was introduced. Angular 17.1.0 does not have this file in the upstream release. TuxCare created url.ts for their 17.1.0 fork (commit e06d36f339 by ejarocki@cloudlinux.com) but...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9181427a-be37-5306-9e33-497fb4d9e72a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 17.1.0-tuxcare.6 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b8a0c6b7-4ea5-58d7-a89b-b0250c41de50",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88058 does not affect version 17.1.0-tuxcare.6 of @angular/forms. not_affected \u2014 The Angular repository (version 17.1.0-tuxcare.5 at SHA 1b802ce320) is not affected by CVE-2026-88058 because it does not contain the vulnerable source code. The vulnerability exists in the domino library's HTML serialization code (lib/NodeUtils.js), which Angular references as a dependency in package.json but does not vendor. The upstream patch (89b20568dfaee1ec8e0b3bcf1872acdddd2f4fef) is a D...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b0582301-4ae3-5321-8844-3bb8d7ca3ffe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 17.1.0-tuxcare.6 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:beb8aa15-cd43-5261-a4e4-0a14c7599eb6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 17.1.0-tuxcare.6 of @angular/forms."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.6"
    }
  ]
}