{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:840d2e82-e204-5c25-83b5-26bdc80f8c48",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/animations",
      "purl": "pkg:npm/%40angular/animations@19.2.21-tuxcare.6",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.6",
      "version": "19.2.21-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f746f0fb-7e2c-5021-b785-72b2f4f59eb2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-27970 does not affect version 19.2.21-tuxcare.6 of @angular/animations. already_fixed \u2014 The target repository (Angular 19.2.21-tuxcare.4) already contains the fix for CVE-2026-27970. The vulnerability (XSS via unsanitized HTML attributes in ICU message translations) has been addressed by TuxCare in prior backports. The defense mechanism in packages/core/src/render3/i18n/i18n_parse.ts lines 829-843 implements the same attribute allowlist validation as the vendor patch, blocking URI...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ab880c02-06ed-5397-a6f3-011e7f91174b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 19.2.21-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b6f09cef-aec2-530c-9ab0-13e12039a555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 19.2.21-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d1c0a3b0-bf21-5beb-a3aa-014dd9ef3596",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 19.2.21-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:568b0ed4-80b9-5ef9-8889-353bac212fa7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 19.2.21-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e50f4182-2ed4-5523-8541-dfbe283ff6e2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 19.2.21-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e70338e7-7de4-59db-a5cc-6147893e3496",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 19.2.21-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6bc89cde-6371-55f5-8b9b-bebed88c4c1a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 19.2.21-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ad486e1d-d544-5bb4-9b97-25cc522c8eb3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 19.2.21-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:08e1314b-4c05-5e80-aea6-91c4d1276efd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 19.2.21-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:add0aa70-259f-5d81-a42f-5c94a74b624c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 19.2.21-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7ff4d4b9-f292-5f04-a613-b7140effd503",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 19.2.21-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ac14a9af-27cf-5522-b8cb-b639efcf0bf7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 19.2.21-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f13ffde3-e1b0-5e1d-a5ff-4108245d1fa9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 19.2.21-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:23326f98-646c-5942-ab46-e8cfdc9f5ba5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 19.2.21-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2cca83a7-82cd-5d05-b13a-a31c4af18f0b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 19.2.21-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:69f648bd-f97d-5f80-81d8-eac643093f72",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 19.2.21-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e1587337-f3df-5b24-a77b-ee73eb1d9f50",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 19.2.21-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d817a359-5f7e-5ae3-b193-ce56faf0bdf5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 19.2.21-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b99fe5e3-28ac-5592-bf3a-0ddd4a8ab831",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 19.2.21-tuxcare.6 of @angular/animations. not_affected \u2014 CVE-2026-88056 does not affect this Angular v19.2.21-tuxcare.5 target. The CVE describes a vulnerability where `String.prototype.trim()` strips Unicode whitespace (U+00A0, U+FEFF) from URLs during SSR, converting same-origin relative paths into cross-origin protocol-relative URLs that leak credentials. The v19.2.x branch uses a simpler URL resolution implementation created by TuxCare (commit 81...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b08c7127-296e-5b62-a231-cc78e90e1ef6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 19.2.21-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3f67af97-eaae-59f3-8d2d-3710c470a622",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 19.2.21-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:79f3f40c-eba6-57b3-800c-2b40169dbb4c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 19.2.21-tuxcare.6 of @angular/animations."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.6"
    }
  ]
}