{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:53a24801-062d-5e5a-8b82-5e976fdac404",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/core",
      "purl": "pkg:npm/%40angular/core@16.2.11-tuxcare.3",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.3",
      "version": "16.2.11-tuxcare.3",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:c5626e6b-1273-5785-afbd-bf8a9b5c6706",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 16.2.11-tuxcare.3 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:16df794b-3511-5c7b-bb5b-b5bc09b7d6b1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.11-tuxcare.3 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:84afd578-cbc8-5163-a50f-54533c26dd06",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 16.2.11-tuxcare.3 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:faf1ecfc-ae44-5924-b4a2-e2af8cbe2f68",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 16.2.11-tuxcare.3 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:a2bde9b6-dde5-5ee0-bd6d-7419348aa0f8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 16.2.11-tuxcare.3 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:e4297912-f852-56b3-b278-5230a2d012ce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 16.2.11-tuxcare.3 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:0b627ca6-ebc8-505d-b358-83744f0f6adb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 16.2.11-tuxcare.3 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:bf4b10fb-92a7-5bb9-bd19-2051537887b9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 16.2.11-tuxcare.3 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:520b6712-b0b5-5781-9583-bf1ed4a48c30",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 16.2.11-tuxcare.3 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:0d94f15f-81f9-5815-b52f-309e227f1aaf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 16.2.11-tuxcare.3 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:a8851865-f278-5ed8-998f-659c66212585",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 16.2.11-tuxcare.3 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:dd10297b-43b5-5909-9b85-7491cb1e7bae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 16.2.11-tuxcare.3 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:4367d728-608e-5331-ba67-06e4a787fca8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 16.2.11-tuxcare.3 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:3c983d06-1907-52fa-979b-e919e600c6e3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 16.2.11-tuxcare.3 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:250617b9-fca1-5aa7-b361-5a2631db08b0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 16.2.11-tuxcare.3 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:5612d3d6-31c4-5cdb-9657-d764090b9e79",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 16.2.11-tuxcare.3 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:99bcaf0c-5e52-586b-ae3b-ef6b10b87124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 16.2.11-tuxcare.3 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:d3afdcca-c086-5c28-95d0-b8d0ae2960e9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 16.2.11-tuxcare.3 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:a24336d0-f52e-5b27-90ac-6e500a2232f0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 16.2.11-tuxcare.3 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:dc883853-5405-5237-827e-2b2706cda3ae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 16.2.11-tuxcare.3 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:0d5f94d7-7cc1-5641-ae95-929cfbea588a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 16.2.11-tuxcare.3 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:d81ba98a-a905-5e8d-ab66-34669ffa46ce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 16.2.11-tuxcare.3 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:39106856-409d-5964-8b18-72451d70e849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 16.2.11-tuxcare.3 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:79538a33-7e4d-5fbf-92dc-4c06ccca1ca2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 16.2.11-tuxcare.3 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:691bbcb8-8abf-538e-a37f-62a8a5a1e51b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.11-tuxcare.3 of @angular/core. not_affected \u2014 Angular 16.2.11-tuxcare.2 is NOT affected by CVE-2026-88056. The vulnerability requires WHATWG URL validation combined with String.prototype.trim() on URLs during SSR, creating a discrepancy that enables SSRF. While the target uses WHATWG URL parsing (backported in commit c03fbfd7cc for CVE-2026-50168), it does NOT call String.prototype.trim() on URLs. The attack chain is broken at the trim() s...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:ed35883c-1126-59b8-92e6-ddd4cf80ff73",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 16.2.11-tuxcare.3 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:f9bdf60d-dce0-5f98-9a88-7694f878aaf5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 16.2.11-tuxcare.3 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:24b37cdc-cbbb-568a-9256-89d9c596c37d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 16.2.11-tuxcare.3 of @angular/core."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.3"
    }
  ]
}