{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ea333e0f-50ec-546d-a19b-ac7013525860",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/service-worker",
      "purl": "pkg:npm/%40angular/service-worker@16.2.12-tuxcare.13",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/service-worker@16.2.12-tuxcare.13",
      "version": "16.2.12-tuxcare.13",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:ca73f25b-53b0-55c0-947e-fc150de80a4e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 16.2.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:a6c8e939-9c30-52de-8094-45f960b00cd8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:24d44ebf-d53c-5e9e-bf3d-f02dff7093e3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 16.2.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:1a897dfc-2828-5c02-925e-1e031c2e6a72",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 16.2.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:091bb968-ec9b-592e-b5d4-15940bb8d1dd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 16.2.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:238e865e-6cd1-59a6-86ad-dc887da3e55e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 16.2.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:9292c318-eb9d-5c1e-9764-4b077765b020",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 16.2.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:2143d069-6a1f-50c1-94c0-151afda41633",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 16.2.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:1bd88dee-ee09-544f-bef7-0dfef64bd72c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 16.2.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:4219b017-5a12-59ad-97b5-dd29d0bb0ed7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 16.2.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:5dc7f826-4dcf-5b2f-b1b0-b4bd7c385a57",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 16.2.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:722c8607-1348-52e7-903e-2a6402cbd379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 16.2.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:616976a5-b184-502f-a4af-e6307e4a14ea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 16.2.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:615330db-25af-524e-a328-89c3c70359cd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 16.2.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:05727679-4fda-5d89-a156-4e31bbc1f2b7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 16.2.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:a4a965f6-b955-5bff-bd6f-b6b49d541d62",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 16.2.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:df4c6f2a-567e-5b8f-871e-853119dba84b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 16.2.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:f86c5298-2b15-55e1-ad67-d06c19e3a267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 16.2.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:a55dde64-d494-57b2-91e8-5f7b96c62c48",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 16.2.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:b9a1f40a-b2a4-561a-aa5c-4707c63b8081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 16.2.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:0fa8cf88-1cc3-56d8-927f-14b0cf7eefb2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 16.2.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:81fca391-31c8-509c-a9d7-cb90ce851195",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 16.2.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:504eaedc-79ac-59f1-8099-269c6f2f88a9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 16.2.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:ceae45f4-9376-527e-aca0-8602f2f683a9",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.12-tuxcare.13 of @angular/service-worker. not_affected \u2014 CVE-2026-88056 affects Angular versions 20.3.x, 21.2.x, and 22.x where a refactored URL parsing utility added String.prototype.trim() that strips Unicode whitespace, enabling SSRF bypasses. The target (Angular 16.2.12-tuxcare.12) is based on Angular 16.2.x architecture, which predates the vulnerable code pattern entirely. TuxCare created url.ts fresh on June 24, 2026 for CVE-2026-50168, modelin...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:990dd8b7-5b71-5cfe-9eb8-46f7d2a90229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 16.2.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:052c1ea9-feff-5873-a9e3-2ce885102804",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 16.2.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@16.2.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:0840d055-67ff-559d-83e2-b9be536bffc5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 16.2.12-tuxcare.13 of @angular/service-worker."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/service-worker@16.2.12-tuxcare.13"
    }
  ]
}