{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:00704a5a-23cd-53c0-b5ce-f28d3724c6a9",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/bazel",
      "purl": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3",
      "version": "16.2.11-tuxcare.3",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:6d0e73a0-08e6-5dbd-809d-17dea09a8a74",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 16.2.11-tuxcare.3 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:f3150ced-7368-5920-93f9-1b5423184900",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.11-tuxcare.3 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:69006c59-2131-59a6-8d89-0758d86420bd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 16.2.11-tuxcare.3 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:98a1aaac-9d81-5615-a388-c8bfc5ab9be2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 16.2.11-tuxcare.3 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:efd04e92-adeb-54a3-acd0-a2b5020cec06",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 16.2.11-tuxcare.3 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:d11ebf4c-7e08-5c4e-9bb6-14fb0ad48027",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 16.2.11-tuxcare.3 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:97431fa8-6367-51fa-a913-65f5e082c128",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 16.2.11-tuxcare.3 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:089b4a08-8a85-52af-9679-895e872a1c92",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 16.2.11-tuxcare.3 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:11bcb04f-7d93-5777-bbea-ceb982d6efb1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 16.2.11-tuxcare.3 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:6790e320-0016-533b-8c18-eaf6106d95e5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 16.2.11-tuxcare.3 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:2ca10129-6518-5cd2-b704-ccb0e278aa84",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 16.2.11-tuxcare.3 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:e1442782-2d36-584c-9fc8-4556dd1cbcd6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 16.2.11-tuxcare.3 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:01613442-c1a6-5406-8a25-b27aa85d3b29",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 16.2.11-tuxcare.3 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:1852ce80-4534-54cc-a17e-1c5dc7082b1e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 16.2.11-tuxcare.3 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:f7b6b35d-61cc-5908-b4b9-66764b73b7b4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 16.2.11-tuxcare.3 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:ce05a29d-f132-52d6-83f1-c0809a967a54",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 16.2.11-tuxcare.3 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:58001d79-0aa5-5b1e-b741-882462b19864",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 16.2.11-tuxcare.3 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:7b8503b7-f6f7-523c-86b9-55d1b76007b6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 16.2.11-tuxcare.3 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:34408713-08a6-5b27-9514-a4e461207548",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 16.2.11-tuxcare.3 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:f5c9ccbf-ea26-548b-bbca-d2569db879b3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 16.2.11-tuxcare.3 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:ba5de2c2-5153-5157-bd3b-fefff9f67837",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 16.2.11-tuxcare.3 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:120883db-443c-5c4d-ad5b-a98df9e0457f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 16.2.11-tuxcare.3 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:6e68f697-7f03-5805-a6c2-a85dfbd83187",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 16.2.11-tuxcare.3 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:26f39916-e7d3-5618-b978-d45a659f9c38",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 16.2.11-tuxcare.3 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:6eed5708-e1c1-5168-9f15-ca0d8eea114b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.11-tuxcare.3 of @angular/bazel. not_affected \u2014 Angular 16.2.11-tuxcare.2 is NOT affected by CVE-2026-88056. The vulnerability requires WHATWG URL validation combined with String.prototype.trim() on URLs during SSR, creating a discrepancy that enables SSRF. While the target uses WHATWG URL parsing (backported in commit c03fbfd7cc for CVE-2026-50168), it does NOT call String.prototype.trim() on URLs. The attack chain is broken at the trim() s...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:55cc863b-ca47-5628-a039-bf2ca64e89f2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 16.2.11-tuxcare.3 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:8a70e8e4-f446-52d9-89aa-0923e2f330a9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 16.2.11-tuxcare.3 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:c0158b5e-4d32-5a24-ab41-a015c7027ecd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 16.2.11-tuxcare.3 of @angular/bazel."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/bazel@16.2.11-tuxcare.3"
    }
  ]
}