{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:19c53a0c-d7b5-5cde-bffb-6ebee047e4ee",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/animations@18.2.12-tuxcare.3",
      "type": "library",
      "name": "@angular/animations",
      "version": "18.2.12-tuxcare.3",
      "purl": "pkg:npm/%40angular/animations@18.2.12-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:5b077f2a-743b-5b55-abd8-13cb35c86f3e",
      "id": "CVE-2025-59052",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 18.2.12-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99d73a0a-cd24-5360-a670-0bd4cd9e4775",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.12-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59ea602b-577b-57e3-9a7e-4820b844515f",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.2.12-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2eddc2a7-3580-551e-8f12-c44be084c75a",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.2.12-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbf6d49d-7fd7-56dd-947c-6b31f2cc4394",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.2.12-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19c316bf-5766-5b56-95d0-5fdcb045c50c",
      "id": "CVE-2026-32635",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.2.12-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1aba22f0-532c-5963-807e-c2ff8899a2b5",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 18.2.12-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4377ae4e-fd36-5f0f-8df9-dcf751e6c50d",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 18.2.12-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e15a1755-4ffa-54ab-b7ff-773c8838695f",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 18.2.12-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a9dc840-3af8-53e2-ac74-6a7c9098b522",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 18.2.12-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfd6513e-339d-5299-b3e1-8de86b5054e7",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 18.2.12-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bd0cafd-48a0-567a-a29f-6a4996ef45e4",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 18.2.12-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:709fb36d-a8f0-5c5c-b3ca-2e0caf00cefb",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 18.2.12-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:308f3b65-2dab-5c79-a40b-4b87bf42fb4a",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50555 does not affect version 18.2.12-tuxcare.3 of @angular/animations. already_fixed \u2014 CVE-2026-50555 fix is already present in the target repository. The vulnerability concerns XSS in domino's noscript element serialization. The fix (escaping matching closing tags and adding NOSCRIPT to raw-text element handling) exists as a patch file that is automatically applied during yarn install via patch-package."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0168c529-ef35-576e-8d91-06ccc5d45a2f",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50556 does not affect version 18.2.12-tuxcare.3 of @angular/animations. already_fixed \u2014 CVE-2026-50556 (XSS via <noscript> raw-text serialization in domino) has been fixed. The target repository contains a committed patch file (tools/esm-interop/patches/npm/domino+2.1.6.patch) that applies the complete fix to the domino dependency. The patch adds NOSCRIPT to the hasRawContent set and removes the conditional _scripting_enabled check, matching the upstream fix exactly. This patch is..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b544f0f-3357-5a7c-bb32-d08d9ae14b81",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 18.2.12-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3587489-b07f-5bce-9d7d-b36cddb913a0",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 18.2.12-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce71dad8-6b08-5d7c-b01b-0d4ec24cbae4",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 18.2.12-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48bbface-8e8b-524f-ba3e-18a5e95cd026",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 18.2.12-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e3b495c-0d4e-5f65-bf4b-e096d9c6a115",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 18.2.12-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6abd3d9c-505b-5022-85e5-6f8ca883850d",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 18.2.12-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e95beef-a516-5e72-97c4-1bc03eac1f99",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 18.2.12-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.12-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/animations@18.2.12-tuxcare.3"
    }
  ]
}