{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a3283b4f-3ba2-567c-b2ac-022fd2b4f40e",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/language-service",
      "purl": "pkg:npm/%40angular/language-service@19.2.21-tuxcare.6",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/language-service@19.2.21-tuxcare.6",
      "version": "19.2.21-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:061f2f2f-da77-5d37-aa11-e05ed1f5128f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-27970 does not affect version 19.2.21-tuxcare.6 of @angular/language-service. already_fixed \u2014 The target repository (Angular 19.2.21-tuxcare.4) already contains the fix for CVE-2026-27970. The vulnerability (XSS via unsanitized HTML attributes in ICU message translations) has been addressed by TuxCare in prior backports. The defense mechanism in packages/core/src/render3/i18n/i18n_parse.ts lines 829-843 implements the same attribute allowlist validation as the vendor patch, blocking URI...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b14b53c6-6ef7-5c01-b9d3-9ec956736cd8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 19.2.21-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a84b3b9d-98b1-5778-810b-4e6bcea994b8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 19.2.21-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:94840588-0e52-5958-be6d-ff620034f48a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 19.2.21-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:773001b3-2e69-5e00-8658-910299f41777",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 19.2.21-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0dda3a22-659c-54d0-afea-d3f3f00f0d9a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 19.2.21-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2ea63244-996b-59f5-b9cd-d41c767c05d2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 19.2.21-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f59d7f68-d825-5b66-949b-d36b2060a10d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 19.2.21-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6948e100-3b6c-5fba-8331-43eb25fb7b9d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 19.2.21-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5cf9b385-e3d3-550d-bef2-62f247eb6590",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 19.2.21-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5cafae65-c3d3-59cd-848b-a49e845f31a1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 19.2.21-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0b33bf42-5c85-51c9-b446-412bf8d1bb7b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 19.2.21-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f986984a-a17a-5680-95a3-e9cfe2d8afa6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 19.2.21-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d07b33cd-2354-538c-a595-6cd8ae59054d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 19.2.21-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:425e9c7d-f482-57a5-a319-22f8f030b7a6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 19.2.21-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7de3e148-c778-5a3d-96c0-a568336a0544",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 19.2.21-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b4346892-a0ad-5a3a-810f-96a8a9ecb793",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 19.2.21-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e7a2b3ce-ef08-59ef-9c4d-83d9e37bbea0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 19.2.21-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e0628846-e638-5b36-8ef1-cb8493edc70e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 19.2.21-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b609f69d-fe01-5402-ba75-1b0f924a48c4",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 19.2.21-tuxcare.6 of @angular/language-service. not_affected \u2014 CVE-2026-88056 does not affect this Angular v19.2.21-tuxcare.5 target. The CVE describes a vulnerability where `String.prototype.trim()` strips Unicode whitespace (U+00A0, U+FEFF) from URLs during SSR, converting same-origin relative paths into cross-origin protocol-relative URLs that leak credentials. The v19.2.x branch uses a simpler URL resolution implementation created by TuxCare (commit 81...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5ea3689f-db28-5bc5-85a9-5f959310be84",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 19.2.21-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:022e5dac-0631-5eb3-8f3b-baed1a650fad",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 19.2.21-tuxcare.6 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@19.2.21-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f7a52f84-dbf3-5c0d-a993-bd6bbb4a928d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 19.2.21-tuxcare.6 of @angular/language-service."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/language-service@19.2.21-tuxcare.6"
    }
  ]
}