{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:db709b54-7cf1-56b8-9ac9-4b3329409e27",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/language-service",
      "purl": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6",
      "version": "17.1.0-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:94e7243c-4984-5f0e-b863-c930a6a984dd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.1.0-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6341b992-aa0f-5e8d-8cad-024709d49b64",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.1.0-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0f3d9051-1032-5392-a3e9-e3be59ccc262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.1.0-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2875ca76-8853-5557-987d-cfb3f7145e47",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 17.1.0-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4f38c908-5218-5fcd-aa19-a1d2df548b51",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.1.0-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:689de1a0-a6b0-533d-b433-e42bd7a628ba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.1.0-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:41480412-312a-538c-a81a-4987a100c9b6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.1.0-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:56503238-e8de-5039-acbd-bf6f80fbf992",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 17.1.0-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:df90bd2b-301c-5f93-b315-15898686124e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.1.0-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7dbffc03-d643-5e09-a060-4071d00ef3de",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.1.0-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:dd553b76-be4b-5e53-a90c-2bfc486aa53f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.1.0-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4ea44cce-dc0a-53de-8247-ac8aed777f3b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.1.0-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8774219e-0916-5e5c-8b58-63af93ec2875",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.1.0-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:540f2ca2-55be-5116-a6e5-f32d163c8818",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.1.0-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:486aa267-e8e2-5d30-acdd-f8ca1408edaa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.1.0-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:461be061-a821-5c12-a98b-e49ea3d970a0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.1.0-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8472ee56-b90b-5fcb-89af-1d962fece1e1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.1.0-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:972a99be-c158-5906-a7c5-901dad16e70b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.1.0-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4c01b721-edff-563e-8c0a-862f49269cb9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.1.0-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1282fd90-21b9-5cde-a97c-b52944881184",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 17.1.0-tuxcare.6 of @angular/language-service. not_affected \u2014 Angular v17.1.0 does not have the TwoWayProperty IR operation that is the subject of CVE-2026-54265. Two-way bindings are desugared into separate property and event bindings before template pipeline processing, with the property half using the same parsePropertyBinding() code path as one-way property bindings, which are properly sanitized.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:969732dd-c5f9-5d4e-8b99-4b55a89f838f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.1.0-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ff36a61d-6adf-57cb-a1bd-443719194a00",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.1.0-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7d0c044d-14ef-500f-8fe1-e605dcd01b27",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.1.0-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:dd3e2e3a-6a18-5b19-90ad-497e1e0af9d4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 17.1.0-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:34dc3b0e-aa2b-54ac-b10e-cec90fa99fee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 17.1.0-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:863d0e26-e6fc-510e-92cb-895bf7341b64",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 17.1.0-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f933d691-9a42-5959-9413-d2a43519e530",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.1.0-tuxcare.6 of @angular/language-service. not_affected \u2014 Angular 17.1.0 was never vulnerable to CVE-2026-88056. The vulnerability exists only in newer Angular versions (v18+, v19+, v20+ before fixes) where a url.ts file with a parseUrl function that uses String.prototype.trim() was introduced. Angular 17.1.0 does not have this file in the upstream release. TuxCare created url.ts for their 17.1.0 fork (commit e06d36f339 by ejarocki@cloudlinux.com) but...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e3713b9e-853a-5004-920e-deba9eea3b0d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 17.1.0-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:844600c6-cdf3-53be-a26f-24f3e821f64b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88058 does not affect version 17.1.0-tuxcare.6 of @angular/language-service. not_affected \u2014 The Angular repository (version 17.1.0-tuxcare.5 at SHA 1b802ce320) is not affected by CVE-2026-88058 because it does not contain the vulnerable source code. The vulnerability exists in the domino library's HTML serialization code (lib/NodeUtils.js), which Angular references as a dependency in package.json but does not vendor. The upstream patch (89b20568dfaee1ec8e0b3bcf1872acdddd2f4fef) is a D...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:38704c10-35d4-5d3f-a75e-4ad6829951c8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 17.1.0-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:df1a502b-6b3a-5dea-9999-3b31e9b3af3e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 17.1.0-tuxcare.6 of @angular/language-service."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.6"
    }
  ]
}