{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fecddd37-5ba5-57c3-9261-c5fbe20ee0ff",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4",
      "type": "library",
      "name": "@angular/forms",
      "version": "18.2.12-tuxcare.4",
      "purl": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:5cb15680-de52-57e0-99e4-b448e9047ba6",
      "id": "CVE-2025-59052",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 18.2.12-tuxcare.4 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ba8b37c-dfdf-5ee4-804f-1f9923077b45",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.12-tuxcare.4 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b28df88-028a-595b-99f4-41f1da15c744",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.2.12-tuxcare.4 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec08b9c9-0a4a-501f-9edf-c7881fe536f0",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.2.12-tuxcare.4 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:daecc0fa-731d-5f7b-82ca-d561b5849447",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.2.12-tuxcare.4 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16dce780-8609-55cb-bf2b-2ec45fb02b5f",
      "id": "CVE-2026-32635",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.2.12-tuxcare.4 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:708cebac-d543-5326-b78d-e7bc910c9014",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 18.2.12-tuxcare.4 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb7c73e7-d974-5105-a866-f8c28f5b83fe",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 18.2.12-tuxcare.4 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f0cc2bd-2e0a-524f-b349-b03bca270771",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 18.2.12-tuxcare.4 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:385e045e-996f-5c09-9d31-bf8add6f0e0d",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 18.2.12-tuxcare.4 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a60d3a45-14a1-503f-ad89-07f7a13544ad",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 18.2.12-tuxcare.4 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f4fd77c-8a1c-5902-937b-0c46048a40ee",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 18.2.12-tuxcare.4 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:846dcff0-8c1f-5dbf-8afd-c01f729a9a71",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 18.2.12-tuxcare.4 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:465af4de-0be9-5721-b555-90f301d2bcc5",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50555 does not affect version 18.2.12-tuxcare.4 of @angular/forms. already_fixed \u2014 CVE-2026-50555 fix is already present in the target repository. The vulnerability concerns XSS in domino's noscript element serialization. The fix (escaping matching closing tags and adding NOSCRIPT to raw-text element handling) exists as a patch file that is automatically applied during yarn install via patch-package."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bb83af9-0701-5303-99cb-a5da5d98ccc2",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50556 does not affect version 18.2.12-tuxcare.4 of @angular/forms. already_fixed \u2014 CVE-2026-50556 (XSS via <noscript> raw-text serialization in domino) has been fixed. The target repository contains a committed patch file (tools/esm-interop/patches/npm/domino+2.1.6.patch) that applies the complete fix to the domino dependency. The patch adds NOSCRIPT to the hasRawContent set and removes the conditional _scripting_enabled check, matching the upstream fix exactly. This patch is..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42016c52-5cc3-571c-8dfa-6c900ce8d051",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 18.2.12-tuxcare.4 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfda4cee-6092-5f4a-b18a-c5903a94d319",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 18.2.12-tuxcare.4 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9fc56f9-9952-52a2-9124-429906efa122",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 18.2.12-tuxcare.4 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7084361c-9eaa-5130-a88c-dfa807420da0",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 18.2.12-tuxcare.4 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e64d81e7-2a2f-5b4e-bf90-d5d6df1dbc04",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 18.2.12-tuxcare.4 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c019e73-f69b-555f-a8da-6afd6d64c011",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 18.2.12-tuxcare.4 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:032f3be8-adbb-5a15-b972-9669bbc3ddb1",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 18.2.12-tuxcare.4 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f60e5335-748e-532d-8ff4-191f15fc3175",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 18.2.12-tuxcare.4 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bf9c76f-ed5f-5456-8ade-904c01366bc9",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 18.2.12-tuxcare.4 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1aeda21-f0b6-5001-b696-72d9ba3d32fb",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 18.2.12-tuxcare.4 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59c15a98-4731-5876-9e27-f34a1b87558f",
      "id": "CVE-2026-88056",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.2.12-tuxcare.4 of @angular/forms. not_affected \u2014 Angular 18.2.12 is NOT affected by CVE-2026-88056. The vulnerable code pattern (parseUrl/resolveUrl using String.prototype.trim() to strip Unicode whitespace) was only introduced in Angular 19+ (May 2026) and never existed in the 18.2.12 release (Nov 2024). The HTTP interceptor in 18.2.12 uses WHATWG URL constructors directly without any trimming, preventing the discrepancy that causes the SSRF..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fa17584-2d4a-503f-b29f-b6b614c63272",
      "id": "CVE-2026-88057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 18.2.12-tuxcare.4 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3830d3b2-2c81-5d26-b2ac-48f57cea9bf8",
      "id": "CVE-2026-88059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 18.2.12-tuxcare.4 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1236448c-d23d-56f9-b3a9-624671ec3361",
      "id": "CVE-2026-88060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 18.2.12-tuxcare.4 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/forms@18.2.12-tuxcare.4"
    }
  ]
}