{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a774611c-aef2-5ae6-a826-677802a753ea",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/platform-browser-dynamic",
      "purl": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16",
      "version": "17.3.12-tuxcare.16",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:9e051db3-3883-5f0d-8fe7-9463d9656f67",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:973cca80-fe0a-5287-9a3f-8874531aab1e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:05794df0-61f7-52e2-9b60-f2571831da3a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:a173d596-fda2-5c42-abb8-e45501bfa7c5",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-101895 does not affect version 17.3.12-tuxcare.16 of @angular/platform-browser-dynamic. not_affected \u2014 The vulnerable code (domino's lib/HTMLParser.js with the after_doctype_name_state infinite loop bug) is NOT present in this Angular source repository. Domino exists only as a declared npm dependency in package.json (line 110: \"domino\": \"https://github.com/angular/domino.git#8f228f8862540c6ccd14f76b5a1d9bb5458618af\"). The BUILD.bazel shows domino is bundled at build time from @npm//:node_modules...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:abc4d235-4ced-5e16-9e28-4feb4e4b2ebc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:673f3e82-25a1-529a-9d9a-36e029c3cf46",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:d4db15a1-cc0a-5a3e-9e51-58c3b59c1bda",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:c04aa3eb-96c1-5494-9f7c-ad9d6903bf98",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:98d31660-955d-5e77-aef8-ba461544b2d4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:2d5d458f-0ba4-55cd-83c6-a62b8666f392",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:a4534560-87fd-5fd3-8de5-941ef74405e7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:43323034-d91b-599c-99c7-a24ec195be6b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:8c62c143-74e7-5d1b-9238-e29b091e57a3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:6f1097f7-596d-5bab-82f8-94b1871881c0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:851dda00-b19d-564a-b91c-bd6cf920d9ff",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:d0a1b71b-d6e9-50bf-b968-b6b8ca383fd1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:5b3e426f-bd81-5bdf-87d0-3de7a32320d2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:4a293354-292b-57ee-96e5-82685e80ab56",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:e722cfc2-a0fe-557c-ac75-155f68560683",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:6be1c104-ed11-5849-8d9e-d5384e73dec3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:4000d054-231d-5ed5-b6ce-1a8f8cc7917b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:b3cbb6ca-f1bb-59d4-8eb5-0e5866dd549d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:07c72833-8d69-50ad-9ae7-00886028e883",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:f191a2db-88ab-528c-9d91-c598d4416f3d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:b9ca47ab-aa6c-52c0-bb94-084ba2b308bc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:0fb8f1a5-e8d8-58e8-920f-fc17d9b2db48",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.3.12-tuxcare.16 of @angular/platform-browser-dynamic. not_affected \u2014 Version 17.3.12 is not affected by CVE-2026-88056. The vulnerability involves String.prototype.trim() being applied during URL resolution in Angular's platform-server, converting validated same-origin URLs with Unicode whitespace into cross-origin protocol-relative URLs, leading to SSRF. This vulnerable code pattern was introduced in newer Angular versions (v20+) and does not exist in version 1...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:c767dce6-da24-5575-b351-e31a2310c20b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:17551a58-f6b0-5958-b341-dac5f7083284",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:441dcc12-f705-54be-9fcc-9a8e828831c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:644480b7-df35-538f-a52e-838c37c71d96",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser-dynamic."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.16"
    }
  ]
}