{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:158872f3-57f4-5944-848b-058a688172aa",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/upgrade",
      "purl": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5",
      "version": "18.1.2-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:70dd585b-fece-5851-85a8-906844bda42c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 18.1.2-tuxcare.5 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ae335019-26cf-53a9-959a-45d3d0ca6b54",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.1.2-tuxcare.5 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d949f7fe-711d-516f-b405-e3f1894492e1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.1.2-tuxcare.5 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:dc9b27dc-8b08-591f-9fa3-6b8ec80554c7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.1.2-tuxcare.5 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5f8fb025-ff42-5b59-bb0b-27ad9e33ef23",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.1.2-tuxcare.5 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:cc46f1db-f479-58a4-a8ee-ec68cf689e26",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.1.2-tuxcare.5 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1bbdd2be-67a4-5a9b-95fd-7ae61d0a81fd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 18.1.2-tuxcare.5 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e6eae82a-44d0-51bd-915f-0a719d561f26",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 18.1.2-tuxcare.5 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c0fbe593-5c36-5d78-a6fd-738a9e045d4f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 18.1.2-tuxcare.5 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2f20e089-eb05-5614-b2e4-84c4086dd02a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 18.1.2-tuxcare.5 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:52df008e-fdc8-5e6e-97b8-66250939fd9c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 18.1.2-tuxcare.5 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:aab4a4ab-32ae-51d5-9823-013de1c45e45",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 18.1.2-tuxcare.5 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:359387b0-f41c-59b4-bcab-271037a925cc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 18.1.2-tuxcare.5 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:30a1d395-a29f-5218-b729-ecd827eb2d81",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50555 does not affect version 18.1.2-tuxcare.5 of @angular/upgrade. already_fixed \u2014 The target Angular 18.1.2 repository has already been patched for this vulnerability. TuxCare commit 32991dd728 'fix all CVEs' added a cumulative domino patch that fixes both the NOSCRIPT XSS vulnerability (CVE-2026-50556, corresponding to the provided patch f74cccd) and the astral Unicode index bug (CVE-2026-50555). The patch is applied automatically to the domino dependency via patch-package ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6266ac8a-0da1-5a30-ad19-ac352816022c",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50556 does not affect version 18.1.2-tuxcare.5 of @angular/upgrade. already_fixed \u2014 CVE-2026-50556 (XSS via noscript raw-text serialization in domino) has been fixed in this Angular repository. The fix is present in tools/esm-interop/patches/npm/domino+2.1.6.patch and is automatically applied to the domino dependency during installation via the postinstall script. The patch was added by TuxCare in commit 32991dd728 on 2026-07-01.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6747a881-1e2c-51f0-a96e-7909698283db",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 18.1.2-tuxcare.5 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3c8effd1-d97c-537f-8741-2a0b67f21328",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 18.1.2-tuxcare.5 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a15de93d-2840-58be-925f-f66c79af0b02",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 18.1.2-tuxcare.5 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:362d06b8-f472-5e22-9ad1-814d9d4d3d20",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 18.1.2-tuxcare.5 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7bd17816-2fc1-5658-94f8-a2f1f6a0dd32",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 18.1.2-tuxcare.5 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ab24d9d9-acb4-5079-b54b-af0a1e336bfd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 18.1.2-tuxcare.5 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9086238f-378e-5343-b233-45cb28145b5c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 18.1.2-tuxcare.5 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5d2cb6e6-f185-5d2e-a79a-100b70a7c079",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 18.1.2-tuxcare.5 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0c955786-21ef-53b3-81f2-8ff2b24f4bb0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 18.1.2-tuxcare.5 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b6bc8d05-e577-52a4-9809-ed1963f22798",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 18.1.2-tuxcare.5 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:633f5bc3-93a1-56ca-a242-3cb173a33528",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.1.2-tuxcare.5 of @angular/upgrade. not_affected \u2014 The target version (Angular 18.1.2) does NOT contain the vulnerable code pattern. CVE-2026-88056 describes a Unicode whitespace trimming vulnerability in Angular SSR's URL resolution, where `String.prototype.trim()` strips characters like U+00A0, converting same-origin paths into protocol-relative cross-origin URLs. The vulnerability was introduced in Angular v20.x during a refactoring (commit ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1d3cc956-99ae-59f6-98be-f3537e06a446",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 18.1.2-tuxcare.5 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a0d1008f-dbde-50f8-bb85-da4150de3ac9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 18.1.2-tuxcare.5 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:df4bd450-3f77-5ba8-b608-1f2afd6cb324",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 18.1.2-tuxcare.5 of @angular/upgrade."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/upgrade@18.1.2-tuxcare.5"
    }
  ]
}