{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f9c80227-2574-5d94-ba01-e467c8af4327",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/platform-browser",
      "purl": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16",
      "version": "17.3.12-tuxcare.16",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:bca6a8e6-cc7b-5cdc-b183-5757b22eeebf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:43193a24-d22b-52a8-85ca-1e32634e03f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:b356f04d-4621-57f2-8e3b-90c3abb69cd4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:ec707c33-9c79-5f60-8d38-a66ee7ce984a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-101895 does not affect version 17.3.12-tuxcare.16 of @angular/platform-browser. not_affected \u2014 The vulnerable code (domino's lib/HTMLParser.js with the after_doctype_name_state infinite loop bug) is NOT present in this Angular source repository. Domino exists only as a declared npm dependency in package.json (line 110: \"domino\": \"https://github.com/angular/domino.git#8f228f8862540c6ccd14f76b5a1d9bb5458618af\"). The BUILD.bazel shows domino is bundled at build time from @npm//:node_modules...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:7a57dfe0-2d96-5b26-a745-233b883c9312",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:84ca47aa-6e9c-5f72-8a2f-2549c5ad8bc3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:869ddccb-d22c-5d92-a155-767748c737e3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:16d388fe-433c-56a2-99a5-3a53b2e437ca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:ce73f67d-adc3-55ee-9216-4747621b4792",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:35e83600-657c-5780-9732-f2db77df707b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:81904182-b755-59c4-be81-c041078e1c9c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:4c13ce62-70a7-5bcb-b36d-7031df27a250",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:aa022fd2-7294-5472-b317-a42594a61a79",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:a088e032-107d-5088-894c-861f1e49d1a4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:05a5561f-a1fe-550f-aeeb-ed567dcae2a8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:11e1f305-041f-54ab-a59b-fd378544204a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:394e9fbc-7a0c-5113-a8e3-07587e3dec15",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:7104fe99-091b-51ea-980c-93a9285cc851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:e41f9219-9e51-5dcb-9ea4-42220cb1139a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:5e6b79f5-41cc-5fa5-864d-c02312b67cb4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:445928b1-3188-53b1-b822-9a47fd38d5b5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:c0bb17fa-e23e-5b48-9213-135c79b41449",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:22423a99-e597-524e-b504-14e3c178fa87",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:e5f8034e-0af7-54ea-a5b1-f1ec686e416b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:dfc564c4-53a8-5fa2-b38c-93ec31c0e04f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:8fa03409-d9f2-5a43-b1c4-ee72021eb406",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.3.12-tuxcare.16 of @angular/platform-browser. not_affected \u2014 Version 17.3.12 is not affected by CVE-2026-88056. The vulnerability involves String.prototype.trim() being applied during URL resolution in Angular's platform-server, converting validated same-origin URLs with Unicode whitespace into cross-origin protocol-relative URLs, leading to SSRF. This vulnerable code pattern was introduced in newer Angular versions (v20+) and does not exist in version 1...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:3c047398-efd5-5c4b-abc9-c2fc5bbcbd82",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:a0ac0133-85b1-56fb-88fb-31716be6538d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:2da4cef5-cc06-5cb0-9355-f8b617c5ea4a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:0e4ccde4-b05d-5489-b8e8-937842d62932",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 17.3.12-tuxcare.16 of @angular/platform-browser."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-browser@17.3.12-tuxcare.16"
    }
  ]
}