{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3bbad378-d858-58b1-a2c7-c2710b3e884b",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/service-worker",
      "purl": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.12",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.12",
      "version": "8.2.14-tuxcare.12",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:48d55e25-5f25-54dc-b6de-cc1ddff7eb72",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 8.2.14-tuxcare.12 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:08f5ac04-3149-5839-868e-76ae4b039787",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 8.2.14-tuxcare.12 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:b050ff1a-f359-5cc6-911a-1b3336c74b43",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 8.2.14-tuxcare.12 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:90983ffe-d742-5261-8528-eeb28e18fa21",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 8.2.14-tuxcare.12 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:fc2a6a12-d90d-53df-91f7-808e20615f2d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 8.2.14-tuxcare.12 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:89163cf3-285f-50df-b502-42875b5ccb88",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 8.2.14-tuxcare.12 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:6222648a-d988-5e8e-b41a-79c90922b623",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 8.2.14-tuxcare.12 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:b96508a1-5231-52e9-8262-41c93e11b11e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 8.2.14-tuxcare.12 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:9a0fb6d7-5b93-5021-a99d-cf793cf1381c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 8.2.14-tuxcare.12 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:4e83a00d-7276-5f6f-87cb-fc9caa013ccb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 8.2.14-tuxcare.12 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:c4bc8b6b-26df-56f3-9f2a-86d0717e91d9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 8.2.14-tuxcare.12 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:f07a9f8d-3705-5e8c-ac7c-dcfd7908913a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 8.2.14-tuxcare.12 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:650012aa-a56e-5b81-a8d8-ce456d7dab9e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 8.2.14-tuxcare.12 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:1d2eae45-eb6b-5776-8602-9d8aa53eecfa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 8.2.14-tuxcare.12 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:ae835b53-3728-507b-be6a-c02eaf648d90",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 8.2.14-tuxcare.12 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:6e503db5-afc3-574a-b965-63368bb991e5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 8.2.14-tuxcare.12 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:f99f012a-ea5c-58b7-847e-c737933b339b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 8.2.14-tuxcare.12 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:9e1a7f60-afa5-59b3-8de7-c1243488c7f8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 8.2.14-tuxcare.12 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:effe5177-0182-540a-a16a-61780256a138",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 8.2.14-tuxcare.12 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:93b723fc-bb2e-5756-bd19-580466d92de7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 8.2.14-tuxcare.12 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:a7eefdf9-6ebd-512f-b4b6-3a4f994889ad",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 8.2.14-tuxcare.12 of @angular/service-worker. not_affected \u2014 Angular 8.2.14 is NOT affected by CVE-2026-68945. The vulnerability exists in HttpTransferCache, a feature that automatically caches HTTP requests during SSR for client hydration. HttpTransferCache was introduced in Angular v16+ and does not exist in version 8.2.14. This version has only a manual TransferState key-value store with no automatic HttpClient integration, and no HTTP caching mechani...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:7e84fc7c-5689-5397-8cf3-82e2a48ddd12",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 8.2.14-tuxcare.12 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:1bf2dfc9-aa7a-5b18-965b-99b5e4b69875",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 8.2.14-tuxcare.12 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:d6a53db6-b444-58dc-85b8-436744a8284f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 8.2.14-tuxcare.12 of @angular/service-worker. not_affected \u2014 Angular 8.2.14 is NOT AFFECTED by CVE-2026-88056. The vulnerability requires a sophisticated URL resolution utility (`parseUrl` in `packages/platform-server/src/url.ts`) that calls `String.prototype.trim()` to strip Unicode whitespace, creating a discrepancy with WHATWG URL validation. This architecture was introduced in Angular v12+ (circa 2026 as TuxCare backports). Angular 8.2.14 (released N...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:4f3be31b-95e1-5102-8ed3-31a815af5139",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 8.2.14-tuxcare.12 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:15099348-7bc1-58ac-871d-a05a18b29b48",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 8.2.14-tuxcare.12 of @angular/service-worker. not_affected \u2014 Angular v8.2.14 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, provideClientHydration(), and withRequestsMadeViaParent() \u2014 all features that do not exist in this version. These features were introduced in Angular v16 (per patches/CVE-2026-50170.patch and patches/CVE-2026-54266.patch). The target uses the legacy NgModule-based HttpClientModule without automatic ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:b4fb5b85-6828-5df3-8ea4-469c95a8ae0e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 8.2.14-tuxcare.12 of @angular/service-worker."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.12"
    }
  ]
}