{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:bf0b0e23-89ad-5db6-86dc-adb50c87ccbd",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/platform-browser-dynamic",
      "purl": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13",
      "version": "8.2.14-tuxcare.13",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:4305495d-91b9-58b6-afc2-4de2c5ab9ce8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 8.2.14-tuxcare.13 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:f4d96dc3-9646-5357-b431-a5045a2c2dbe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 8.2.14-tuxcare.13 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:f2863a69-2a5d-52ad-9087-f27a01cfd42e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 8.2.14-tuxcare.13 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:23363dc5-f19a-5ab8-96dd-256a6b73d22b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-101895 does not affect version 8.2.14-tuxcare.13 of @angular/platform-browser-dynamic. not_affected \u2014 CVE-2026-101895 describes a DoS vulnerability in domino's HTML parser where incomplete DOCTYPE declarations with trailing whitespace cause infinite loops. The vulnerable code (domino's after_doctype_name_state EOF handling in HTMLParser.js) is NOT present in this Angular repository. Domino version 2.1.2 is declared as a dependency in @angular/platform-server's package.json but is not vendored i...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:7599b5a9-046b-53e6-9a6d-29bf56507ead",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 8.2.14-tuxcare.13 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:43fafe3a-86ce-5519-8435-99ab093bb6de",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 8.2.14-tuxcare.13 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:1bf32137-b0bb-56f0-a7e6-48b1156054fa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 8.2.14-tuxcare.13 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:87436e1e-ff7d-5952-91b3-6934c4ccce8b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 8.2.14-tuxcare.13 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:ffad86c8-fd12-53a2-b83b-e5526ab54ef3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 8.2.14-tuxcare.13 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:fe284988-7db7-576f-b758-25620b461844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 8.2.14-tuxcare.13 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:152d7593-e78e-5d3f-9d4a-14c694763b82",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 8.2.14-tuxcare.13 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:53f40630-7bb0-5d6c-9c8d-4d8eacf1f521",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 8.2.14-tuxcare.13 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:070d3c6e-17ce-5acd-b2ff-ef28b4048f63",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 8.2.14-tuxcare.13 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:fb27231b-40c5-541e-9a58-669a9b9715b0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 8.2.14-tuxcare.13 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:12ddc144-eb07-58e9-8801-f1e05e46c899",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 8.2.14-tuxcare.13 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:511bdd41-61dd-5571-81a9-9b055ffe25e4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 8.2.14-tuxcare.13 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:d2e6dffc-9e52-534b-9a96-c9dc63728114",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 8.2.14-tuxcare.13 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:e9db2062-2467-59de-bf65-60d17c938a61",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 8.2.14-tuxcare.13 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:366ab19d-166b-5817-9b0f-b33c63233bfc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 8.2.14-tuxcare.13 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:0be9a0c7-a5e7-5788-b6c2-1810fd50561c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 8.2.14-tuxcare.13 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:fd2d6e05-e4bc-5aff-9259-f29decbdfa15",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 8.2.14-tuxcare.13 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:c5e27d9b-3770-574c-87cb-fd47494d7a65",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 8.2.14-tuxcare.13 of @angular/platform-browser-dynamic. not_affected \u2014 Angular 8.2.14 is NOT affected by CVE-2026-68945. The vulnerability exists in HttpTransferCache, a feature that automatically caches HTTP requests during SSR for client hydration. HttpTransferCache was introduced in Angular v16+ and does not exist in version 8.2.14. This version has only a manual TransferState key-value store with no automatic HttpClient integration, and no HTTP caching mechani...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:badd88f6-3ee9-5c36-97de-8259cc80d7d6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 8.2.14-tuxcare.13 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:ac8e4ccd-97b5-5bc7-9c18-effcd2ec3503",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 8.2.14-tuxcare.13 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:b8f6c065-1484-510c-95e2-d88c32ce90bb",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 8.2.14-tuxcare.13 of @angular/platform-browser-dynamic. not_affected \u2014 Angular 8.2.14 is NOT AFFECTED by CVE-2026-88056. The vulnerability requires a sophisticated URL resolution utility (`parseUrl` in `packages/platform-server/src/url.ts`) that calls `String.prototype.trim()` to strip Unicode whitespace, creating a discrepancy with WHATWG URL validation. This architecture was introduced in Angular v12+ (circa 2026 as TuxCare backports). Angular 8.2.14 (released N...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:9c97e2a1-8cd8-54e7-a503-39078cd41d39",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 8.2.14-tuxcare.13 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:0210bb71-fc8e-5330-a421-1b2898ab616b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 8.2.14-tuxcare.13 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:0380aef2-aa21-5784-ae94-1f1118a23c18",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 8.2.14-tuxcare.13 of @angular/platform-browser-dynamic. not_affected \u2014 Angular v8.2.14 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, provideClientHydration(), and withRequestsMadeViaParent() \u2014 all features that do not exist in this version. These features were introduced in Angular v16 (per patches/CVE-2026-50170.patch and patches/CVE-2026-54266.patch). The target uses the legacy NgModule-based HttpClientModule without automatic ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:5d8cf912-23fe-5e17-8a01-9f411babab0d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 8.2.14-tuxcare.13 of @angular/platform-browser-dynamic."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-browser-dynamic@8.2.14-tuxcare.13"
    }
  ]
}