{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8da3172b-cab7-5e8c-884e-900107279186",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.12",
      "type": "library",
      "name": "@angular/core",
      "version": "16.2.12-tuxcare.12",
      "purl": "pkg:npm/%40angular/core@16.2.12-tuxcare.12"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e2ec9291-3da7-59c5-9daf-e9b7572c28bc",
      "id": "CVE-2025-59052",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 16.2.12-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc89ac21-7f3a-50f0-a435-f52327dfe941",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.12-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2fe2efe-12a8-50bd-9118-3c729b41458e",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 16.2.12-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90954076-f05d-5619-87ed-47c35a12fc6a",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 16.2.12-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ad52564-c312-5f84-a828-30b7c5192aec",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 16.2.12-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e72afec-9821-5459-8213-4190388d28bf",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 16.2.12-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56419c22-ab2a-5ad4-8adb-fd9ce38ffd24",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 16.2.12-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8667aa3d-bb52-58d8-8601-0dac786c45e1",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 16.2.12-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c1e8e0f-1bf9-51e3-8496-a150cdbacd14",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 16.2.12-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59ccdd3f-64d6-5568-98ad-d85cbcf1befe",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 16.2.12-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56df2613-6a88-5148-910c-8c7b970e3327",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 16.2.12-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abf5b260-eb0a-5d7a-acc9-48ec3996f1fa",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 16.2.12-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb8a33e5-0bd8-51c9-8cc9-d7793b18af3b",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 16.2.12-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:072926f4-fe9f-560e-948e-08f3232f937e",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 16.2.12-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29ffd1cf-38d2-5748-ac83-ef023569dbc8",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 16.2.12-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81162f6d-97f0-5aaf-ac8d-4237d0a262b4",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 16.2.12-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6eb91d6-475c-5185-b84a-4863886fe2fa",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 16.2.12-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4eb1157-d63c-5c5d-9de3-3f0f736d4e08",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 16.2.12-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ce3874a-096f-51ea-ad39-c406f8107470",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 16.2.12-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f8a50b3-7afb-5a89-9bd8-e906ae5f0394",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 16.2.12-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f37c31a-89f7-5e42-b13f-7c9f59261567",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 16.2.12-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c759341-8cf8-5491-b246-302a48fdd517",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 16.2.12-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:039f5b61-d9b1-5591-bfdf-ec9719cdc5e8",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 16.2.12-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7e48d6a-0560-5e0f-8d41-7166fd227efd",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 16.2.12-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e00f119-6154-56fd-a939-3b59829607d2",
      "id": "CVE-2026-88056",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.12-tuxcare.12 of @angular/core. not_affected \u2014 CVE-2026-88056 affects Angular versions 20.3.x, 21.2.x, and 22.x where a refactored URL parsing utility added String.prototype.trim() that strips Unicode whitespace, enabling SSRF bypasses. The target (Angular 16.2.12-tuxcare.12) is based on Angular 16.2.x architecture, which predates the vulnerable code pattern entirely. TuxCare created url.ts fresh on June 24, 2026 for CVE-2026-50168, modelin..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0de6ae40-ffc3-5a33-9371-91fd683966ee",
      "id": "CVE-2026-88057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 16.2.12-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa66f134-d42a-518f-bbf6-00ed324a05dd",
      "id": "CVE-2026-88059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 16.2.12-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19e565f5-df6c-5d24-8b36-3311e47e1da6",
      "id": "CVE-2026-88060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 16.2.12-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.12"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.12"
    }
  ]
}