{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2ef4b5ff-3ab6-5e50-9535-168c4db097aa",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/animations@19.2.23-tuxcare.1",
      "type": "library",
      "name": "@angular/animations",
      "version": "19.2.23-tuxcare.1",
      "purl": "pkg:npm/%40angular/animations@19.2.23-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a2142753-c2ef-5d11-a412-477e0544ff83",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-27970 does not affect version 19.2.23-tuxcare.1 of @angular/animations. already_fixed \u2014 The target repository (Angular 19.2.23) already contains the fix for CVE-2026-27970. The vulnerability patch was applied via TuxCare backport commit 1d55ab497ceebdc7624f3357deac1d4c9c30171a on July 1, 2026, two days before the target version SHA (July 3, 2026). The fix converts ICU message attribute handling from implicit trust to explicit allowlist validation, blocks all URI attributes with 'u..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.23-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21149fe1-4579-52df-8968-3b6e015793aa",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 19.2.23-tuxcare.1 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.23-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77dc7237-237a-50bc-bb79-85f386e3acca",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 19.2.23-tuxcare.1 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.23-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3db1c68d-3fa8-52c9-b5cf-50f9ce55fb39",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 19.2.23-tuxcare.1 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.23-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd04044a-0ebe-51d5-8274-5aa8c4d737ee",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 19.2.23-tuxcare.1 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.23-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a0fc122-8c9f-573a-b0ec-7cef1199e3a6",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 19.2.23-tuxcare.1 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.23-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:872da4a6-6271-577a-ab2e-0d490b997f93",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 19.2.23-tuxcare.1 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.23-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de02ae6f-a0f8-5d15-8ed6-d1a61ec3a6ee",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 19.2.23-tuxcare.1 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.23-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3eecdf8-d7f3-5c65-9369-8a9dd1c43baa",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 19.2.23-tuxcare.1 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.23-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/animations@19.2.23-tuxcare.1"
    }
  ]
}