{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:456ceff7-b220-5f97-a571-4c929746a364",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/service-worker",
      "purl": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16",
      "version": "17.3.12-tuxcare.16",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:66e1fa88-902d-50a9-ba80-4ac3dbbab123",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.3.12-tuxcare.16 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:8f9d1c0c-5c67-5c69-9fff-7b97a45a1f75",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.3.12-tuxcare.16 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:582dd2e3-e1a8-57c5-9cb7-fcdcb598b910",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.3.12-tuxcare.16 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:8103aecf-120a-5f12-a941-279ee9a775f0",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-101895 does not affect version 17.3.12-tuxcare.16 of @angular/service-worker. not_affected \u2014 The vulnerable code (domino's lib/HTMLParser.js with the after_doctype_name_state infinite loop bug) is NOT present in this Angular source repository. Domino exists only as a declared npm dependency in package.json (line 110: \"domino\": \"https://github.com/angular/domino.git#8f228f8862540c6ccd14f76b5a1d9bb5458618af\"). The BUILD.bazel shows domino is bundled at build time from @npm//:node_modules...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:998da0e5-7b82-5a68-ac3e-5af8200c0be6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.3.12-tuxcare.16 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:5c600d96-20cd-5e88-a8db-0b0e6c5c7ac6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.3.12-tuxcare.16 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:8028e61f-8a25-5cc4-8267-5580cc6807ee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.3.12-tuxcare.16 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:80a53f99-2755-5495-831d-36712bb186c1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.3.12-tuxcare.16 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:3f740599-72f4-5c39-97cc-6de7d1940707",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.3.12-tuxcare.16 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:372486da-f92a-5ee3-8e85-b30f4a776794",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.3.12-tuxcare.16 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:7b7e04be-f517-55c4-bb08-7d26128d719e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.3.12-tuxcare.16 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:47467ffc-c1e8-5b7a-9c18-0e75a685e72c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.3.12-tuxcare.16 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:17e67fe1-1ca3-568d-ac27-c199b90bfb7f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.3.12-tuxcare.16 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:636eb4de-82ed-54e8-bb01-69e7637311d0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.3.12-tuxcare.16 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:b5f3ec07-d372-5c10-b26e-885a81eb2ca0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.3.12-tuxcare.16 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:a6e1eca0-f3e2-5999-b8e6-9dee5f1c9d22",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.3.12-tuxcare.16 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:e6a51c06-7b84-5234-9a12-2e7b67cece38",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.3.12-tuxcare.16 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:830a4baa-1426-58be-b9dc-60f62fcab8a2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.3.12-tuxcare.16 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:de5422f4-b6a6-5bd6-aa90-b83edb02abdf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 17.3.12-tuxcare.16 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:39270a85-909a-50d1-86e1-eb02b9c95c29",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.3.12-tuxcare.16 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:609b350c-6025-5533-bf70-d19cb4ebd9f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.3.12-tuxcare.16 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:6e4a1da3-3972-545c-b3db-325434eb2094",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.3.12-tuxcare.16 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:a958212f-9810-5fb7-b8d0-80d7f39bce98",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 17.3.12-tuxcare.16 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:68989d9c-6968-5b60-9be6-15677bd2aeee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 17.3.12-tuxcare.16 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:86340737-6189-552d-a67d-79df2f21af42",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 17.3.12-tuxcare.16 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:b77f49f4-ecb8-5ac7-8486-b34466db5cda",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.3.12-tuxcare.16 of @angular/service-worker. not_affected \u2014 Version 17.3.12 is not affected by CVE-2026-88056. The vulnerability involves String.prototype.trim() being applied during URL resolution in Angular's platform-server, converting validated same-origin URLs with Unicode whitespace into cross-origin protocol-relative URLs, leading to SSRF. This vulnerable code pattern was introduced in newer Angular versions (v20+) and does not exist in version 1...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:1423512e-2bc7-5967-92e5-8615b57ef786",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 17.3.12-tuxcare.16 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:2f0f4a2e-09d9-5b3a-9857-bef433818d0e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 17.3.12-tuxcare.16 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:78ad0eb3-60a5-50db-acf8-b015fc5aaaca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 17.3.12-tuxcare.16 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:83a6d7f8-f8d2-51f4-ae77-8d40bfbeca02",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 17.3.12-tuxcare.16 of @angular/service-worker."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.16"
    }
  ]
}