{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5c5626d0-bc4d-5908-8619-233eace71f24",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/service-worker",
      "purl": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5",
      "version": "17.1.0-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d348d58b-aa64-5615-b9de-687df05f236d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.1.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:84a20b28-5bab-53a7-af28-857772eb6210",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.1.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c875d11e-eb69-5a9d-9ea8-e5df67e9f8d7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.1.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:fea2034f-f618-5d3b-a8bb-620e7d2c33fa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.1.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9a4bd633-f713-5100-8ebe-aac5d7356e4f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.1.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:525f0b31-a3c3-57e4-b6fd-bff2f1f8f5eb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.1.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:af02a1ff-44c5-5733-a3b7-345f6c846f24",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 17.1.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c3fcbee4-a28e-5475-85c5-1ceac36c629c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.1.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a6927852-c416-560c-97a3-98c673f8635a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.1.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d0c4f025-cd41-598a-a5cb-69ff905f64ba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.1.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:72e6bf8c-3a6a-5e37-9159-de754cd9c20a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.1.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:cf02a520-5d29-5d50-8a7d-6905935b5e3c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.1.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:859ff171-bbd7-5a25-af3c-1a971e4091ab",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.1.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4495c705-e1e8-5101-8ab9-707742541d89",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.1.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:da1efd75-6b83-5f9c-8f8f-009c9d59b2aa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.1.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2fa2d45a-6f7f-5f04-8c9b-1584dffe3793",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.1.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a5d46ef5-5340-5ab7-86de-bfc17062eeec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.1.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:65a1a620-b89d-5b72-adb1-0d60d41953a1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.1.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8bc76fed-7cb5-5340-a4dd-5dc8c0566119",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 17.1.0-tuxcare.5 of @angular/service-worker. not_affected \u2014 Angular v17.1.0 does not have the TwoWayProperty IR operation that is the subject of CVE-2026-54265. Two-way bindings are desugared into separate property and event bindings before template pipeline processing, with the property half using the same parsePropertyBinding() code path as one-way property bindings, which are properly sanitized.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:538fd948-3fb1-57dc-b862-7bd601094bc5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.1.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:fed90652-1072-5181-b563-95c5711b3e32",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.1.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:91330060-b500-5b19-b827-2d2c48ef5624",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.1.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ac916048-0ea9-5eb5-9cc3-0bceb6392504",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 17.1.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:687c77c4-d58c-5d9e-8475-f8ef1b53dc2e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 17.1.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e46297c4-a4a9-54fb-acdd-97a941c2cdaa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 17.1.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:508f58e6-3360-55c4-aa35-7409c995c9b9",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.1.0-tuxcare.5 of @angular/service-worker. not_affected \u2014 Angular 17.1.0 was never vulnerable to CVE-2026-88056. The vulnerability exists only in newer Angular versions (v18+, v19+, v20+ before fixes) where a url.ts file with a parseUrl function that uses String.prototype.trim() was introduced. Angular 17.1.0 does not have this file in the upstream release. TuxCare created url.ts for their 17.1.0 fork (commit e06d36f339 by ejarocki@cloudlinux.com) but...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ba88f11e-0202-5847-b772-a3866ae57282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 17.1.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:bc38179e-449b-503e-91e6-766823f795e5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 17.1.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:791886e1-9c90-5d93-9a60-50771b0aa82a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 17.1.0-tuxcare.5 of @angular/service-worker."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/service-worker@17.1.0-tuxcare.5"
    }
  ]
}