{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:939dddb6-ffb9-5509-a37a-2419c0b1b472",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/service-worker",
      "purl": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13",
      "version": "8.2.14-tuxcare.13",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:ed9cf862-4a34-5db4-8696-b5a94205acf1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 8.2.14-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:468b7c91-fb4d-596a-a4ed-1ee5d6ed134d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 8.2.14-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:0ad4d021-3161-5a26-9d14-79b62a1d5e2c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 8.2.14-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:812ee840-ecf4-50ff-a254-24f85314d227",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-101895 does not affect version 8.2.14-tuxcare.13 of @angular/service-worker. not_affected \u2014 CVE-2026-101895 describes a DoS vulnerability in domino's HTML parser where incomplete DOCTYPE declarations with trailing whitespace cause infinite loops. The vulnerable code (domino's after_doctype_name_state EOF handling in HTMLParser.js) is NOT present in this Angular repository. Domino version 2.1.2 is declared as a dependency in @angular/platform-server's package.json but is not vendored i...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:69ea14a4-9771-5c38-97a4-bcf1f2d3e9d4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 8.2.14-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:3c0b519f-42f1-59f9-ac08-5eb3dff12f56",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 8.2.14-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:b3aa3483-2c3d-5ac1-be99-408422875c97",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 8.2.14-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:977af384-96f5-5380-bb04-7a180c9854e8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 8.2.14-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:f6789358-2c72-5034-a181-78de8d2d6f02",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 8.2.14-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:39a5cd7b-7db3-5943-b7f1-f8a53ec4af94",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 8.2.14-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:a4713117-c4a2-5bdb-87c9-ebdedb51f6cc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 8.2.14-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:81034103-77d0-5a28-8a85-48307c2310fc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 8.2.14-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:a342fba1-fe22-5204-b122-4efe58781d46",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 8.2.14-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:a4af4a00-912f-5a60-b966-89aeedf41778",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 8.2.14-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:18e5d208-3682-59f5-b9b6-e5f3a20809f5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 8.2.14-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:53c0f0c7-b0b8-561b-9ff5-dd84e5d951b0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 8.2.14-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:d74151c0-122e-5ee9-8402-6e0f271be401",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 8.2.14-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:68a00daa-b05c-538e-8793-5a0a66987910",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 8.2.14-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:c6f808f1-a900-53c7-bee2-80c01186933e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 8.2.14-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:4272f3cd-9bbf-56d0-93bf-6b5ac2605991",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 8.2.14-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:7527ca6f-7dd6-53af-b1ad-ff50c1beffad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 8.2.14-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:da92dc3c-a0b0-5374-891f-d29cfd317cdc",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 8.2.14-tuxcare.13 of @angular/service-worker. not_affected \u2014 Angular 8.2.14 is NOT affected by CVE-2026-68945. The vulnerability exists in HttpTransferCache, a feature that automatically caches HTTP requests during SSR for client hydration. HttpTransferCache was introduced in Angular v16+ and does not exist in version 8.2.14. This version has only a manual TransferState key-value store with no automatic HttpClient integration, and no HTTP caching mechani...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:1de278f6-44a9-5883-8b88-f16219f789fa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 8.2.14-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:2f2b1404-c7a7-5bca-aac5-f31feb4cc39f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 8.2.14-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:1704ecbd-545e-5751-bb36-1ac1a581b205",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 8.2.14-tuxcare.13 of @angular/service-worker. not_affected \u2014 Angular 8.2.14 is NOT AFFECTED by CVE-2026-88056. The vulnerability requires a sophisticated URL resolution utility (`parseUrl` in `packages/platform-server/src/url.ts`) that calls `String.prototype.trim()` to strip Unicode whitespace, creating a discrepancy with WHATWG URL validation. This architecture was introduced in Angular v12+ (circa 2026 as TuxCare backports). Angular 8.2.14 (released N...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:33b44891-1884-5850-90c7-ff696ba40c29",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 8.2.14-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:be42e350-f788-5ede-9007-3745d1a89591",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 8.2.14-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:63fdbc60-0fa4-5979-8833-fa84289a6acc",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 8.2.14-tuxcare.13 of @angular/service-worker. not_affected \u2014 Angular v8.2.14 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, provideClientHydration(), and withRequestsMadeViaParent() \u2014 all features that do not exist in this version. These features were introduced in Angular v16 (per patches/CVE-2026-50170.patch and patches/CVE-2026-54266.patch). The target uses the legacy NgModule-based HttpClientModule without automatic ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:d6d34fd8-3823-5599-93c3-8147016421e3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 8.2.14-tuxcare.13 of @angular/service-worker."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.13"
    }
  ]
}