{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6020ae33-1476-5d58-83e6-c8cbea6aa3cb",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/service-worker",
      "purl": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8",
      "version": "8.0.3-tuxcare.8",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:2a033d48-6373-57b5-aabb-b2bdd7e1cc8c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 8.0.3-tuxcare.8 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:026f32dc-7675-50c7-9fdf-1bd7bff76308",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 8.0.3-tuxcare.8 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:55b71a59-4878-5f96-a3d1-48ea198e84c3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 8.0.3-tuxcare.8 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:a1e7c040-29d5-5f61-8793-b1509b631353",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 8.0.3-tuxcare.8 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:e9a0aafc-9485-56fe-b028-b650459346a0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 8.0.3-tuxcare.8 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:ff161094-1a0b-50d4-9e77-f60c0ad845c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 8.0.3-tuxcare.8 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:1bf795a3-46c4-5df4-9fb2-fa25893d2cf3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41423 does not affect version 8.0.3-tuxcare.8 of @angular/service-worker. not_affected \u2014 The target Angular version 8.0.3 is not affected by CVE-2026-41423. The vulnerability requires WHATWG URL API (introduced in Angular 8.2.x+) to manifest the hostname override behavior. Version 8.0.3 uses Node.js legacy url.parse() which does not interpret protocol-relative URLs as having attacker-controlled hostnames.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:de2ea571-03ec-52a5-aba7-facb75de31a8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 8.0.3-tuxcare.8 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f19d2574-36c4-5a10-bfcf-797c1e6743e4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 8.0.3-tuxcare.8 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:cbf1323f-078e-583f-933a-4ff68344affb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 8.0.3-tuxcare.8 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:78552a2c-1df2-55d5-ac6c-2f854e58c7b2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50170 does not affect version 8.0.3-tuxcare.8 of @angular/service-worker. not_affected \u2014 The target Angular v8.0.3 is NOT affected by CVE-2026-50170. The vulnerability requires the HTTP transfer cache feature (packages/common/http/src/transfer_cache.ts) and client hydration mechanisms, which were introduced in Angular v16+. This version lacks the entire affected component.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:7c5af482-0dbe-55f1-ab28-ae263ab140ad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 8.0.3-tuxcare.8 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:d437e962-ee04-5a2d-a164-df0bbf89a8d9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 8.0.3-tuxcare.8 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:dbcbf4fd-78a7-51aa-88af-8c88edf13791",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 8.0.3-tuxcare.8 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:85998c10-2f50-5d88-b015-5ae4a986dc7c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 8.0.3-tuxcare.8 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f2335d26-1f28-5d2d-b00d-c8a86a5c307b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 8.0.3-tuxcare.8 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:35c527ac-eac4-57ae-a927-5f91d41c45f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 8.0.3-tuxcare.8 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:52001057-f657-523e-b766-c75574102569",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54264 does not affect version 8.0.3-tuxcare.8 of @angular/service-worker. not_affected \u2014 The target Angular service-worker version 8.0.3-tuxcare.4 is NOT AFFECTED by CVE-2026-54264. The vulnerability requires the service worker to copy and forward request headers during cross-origin redirects. This version never copies headers: the AssetGroup path creates fresh requests from URLs only (no header preservation), and the DataGroup path delegates to the browser's spec-compliant fetch A...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:910538a5-b5a8-5752-8493-c1a64363a3e9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 8.0.3-tuxcare.8 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:25f5038f-806e-5279-af0e-56c52eb98633",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54266 does not affect version 8.0.3-tuxcare.8 of @angular/service-worker. not_affected \u2014 Angular 8.0.3-tuxcare.4 is NOT affected by CVE-2026-54266. The vulnerable HttpTransferCache feature with its weak DJB2 hash-based cache key generation does not exist in this version. HttpTransferCache was introduced in Angular v16+, while this target is v8.0.3.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:8a3e2ac8-7b69-5158-96ef-5b099ffd1cbd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 8.0.3-tuxcare.8 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:36385311-b691-59a7-a253-77e22ba233ed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 8.0.3-tuxcare.8 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:0d3f8b76-f670-5e48-ae56-d4cb2b08d0ad",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 8.0.3-tuxcare.8 of @angular/service-worker. not_affected \u2014 Angular 8.0.3-tuxcare.5 is NOT AFFECTED by CVE-2026-68945. The vulnerability concerns HttpTransferCache, a feature that caches HTTP requests during Server-Side Rendering (SSR) and generates cache keys that incorrectly treat scalar-comma parameters (role=user,admin) as identical to repeated parameters (role=user&role=admin). This feature does not exist in Angular 8.0.3 \u2014 it was introduced in Ang...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:9abf04b0-42cf-57e9-9aeb-960650fe826d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 8.0.3-tuxcare.8 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f1585bf3-7e27-5115-9901-2095804b0364",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 8.0.3-tuxcare.8 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:4889d93e-757c-5f88-ae83-7150efe5b5b2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 8.0.3-tuxcare.8 of @angular/service-worker. not_affected \u2014 Angular 8.0.3 is not affected by CVE-2026-88056. The vulnerability exists only in later Angular versions (v19+, v20+, v21+, v22+) where packages/platform-server/src/url.ts contains a parseUrl function that calls String.prototype.trim() on URL strings. This trim() call strips Unicode whitespace (U+00A0, U+FEFF), converting same-origin URLs into cross-origin protocol-relative URLs, causing SSRF. ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:41866375-86d5-5523-95f3-6fd91c82dad0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 8.0.3-tuxcare.8 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:079832fd-f093-51af-ba9d-d44b8c22c6de",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 8.0.3-tuxcare.8 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:79d76ca5-b49e-5654-ae0f-5a1ce67dab7a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 8.0.3-tuxcare.8 of @angular/service-worker. not_affected \u2014 Angular v8.0.3 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache, withRequestsMadeViaParent(), and modern SSR hydration features that were introduced in Angular v16+. Version 8.0.3 predates these features by multiple major releases. The legacy TransferState in v8 is a manual key-value store with no integration with HttpClient, making the described attack chain impo...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:590ca034-57b7-55a1-b8e7-2b55fee45e6d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 8.0.3-tuxcare.8 of @angular/service-worker."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/service-worker@8.0.3-tuxcare.8"
    }
  ]
}