{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:65078137-d0ea-5341-8a65-fc0602049891",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14",
      "type": "library",
      "name": "@angular/service-worker",
      "version": "17.3.12-tuxcare.14",
      "purl": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9f85693b-43cf-52a6-b536-1d9aa1be5923",
      "id": "CVE-2025-59052",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.3.12-tuxcare.14 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48ba9c2b-f05a-5af7-9e3b-bb9c37960466",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.3.12-tuxcare.14 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0eafe4ea-3d51-5d42-a3fc-3ea1b89bc037",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.3.12-tuxcare.14 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a04bf005-8e2b-5176-9107-d54d89846541",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.3.12-tuxcare.14 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cc672a9-4479-5244-a323-c8b7c2afa6e4",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.3.12-tuxcare.14 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9873de73-e753-58f4-86db-81df0be62372",
      "id": "CVE-2026-32635",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.3.12-tuxcare.14 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ff0f9df-bc05-5138-9696-d20a2e8ae674",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 17.3.12-tuxcare.14 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e07f3e43-6414-5929-8085-395ef48913bc",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.3.12-tuxcare.14 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cec7edd9-b3fe-5cfe-9bde-ee8f3597016d",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.3.12-tuxcare.14 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:585dfaa3-d909-5e83-98f9-c458b6964c13",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.3.12-tuxcare.14 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb33b163-c0c9-53d2-abe9-47f34f92833c",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.3.12-tuxcare.14 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54370a6a-fca1-5fdb-b4d5-9c2277be3850",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.3.12-tuxcare.14 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba87406e-1b04-5e0b-b283-371c422dd9e6",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.3.12-tuxcare.14 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb0b9dba-e9e8-5866-971f-d94659111f3d",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.3.12-tuxcare.14 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01e07d64-6ba9-5321-b943-caf31dcbf4af",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.3.12-tuxcare.14 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56b53d7b-6599-50d5-a7de-56cc339202ef",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.3.12-tuxcare.14 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f524daf-52a7-5430-a5d4-ba4ced277284",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.3.12-tuxcare.14 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8544d3bb-60ad-53c9-ae02-40b7829aa5ff",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.3.12-tuxcare.14 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:793a521a-012d-5fd0-805f-bd122255b322",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 17.3.12-tuxcare.14 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bad70dd8-ad75-5592-a70d-a59e27828ac2",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.3.12-tuxcare.14 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27ed951c-4946-5cfb-9f8a-1da14f29c574",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.3.12-tuxcare.14 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc2295d2-d057-5389-9e32-0c310c474035",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.3.12-tuxcare.14 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e029108-02f1-5cb7-b589-18fdd1836188",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 17.3.12-tuxcare.14 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb8af1a4-e53b-5513-ac3e-5c6f845deef9",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 17.3.12-tuxcare.14 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43769c11-0e32-5f65-b6cc-e570fa3856e3",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 17.3.12-tuxcare.14 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d0788f9-5153-551b-ae08-1c7febea248f",
      "id": "CVE-2026-88056",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.3.12-tuxcare.14 of @angular/service-worker. not_affected \u2014 Version 17.3.12 is not affected by CVE-2026-88056. The vulnerability involves String.prototype.trim() being applied during URL resolution in Angular's platform-server, converting validated same-origin URLs with Unicode whitespace into cross-origin protocol-relative URLs, leading to SSRF. This vulnerable code pattern was introduced in newer Angular versions (v20+) and does not exist in version 1..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3beb3c8b-be82-545f-9c05-4f87eeb84756",
      "id": "CVE-2026-88057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 17.3.12-tuxcare.14 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:742a84bf-3d3c-5270-9653-384e85cdb82e",
      "id": "CVE-2026-88059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 17.3.12-tuxcare.14 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9f72aa7-ced9-532a-8125-72d0186b0f88",
      "id": "CVE-2026-88060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 17.3.12-tuxcare.14 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.14"
    }
  ]
}