{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e0df003c-9ce9-568e-8cdc-28ac3dfbd040",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.2",
      "type": "library",
      "name": "@angular/bazel",
      "version": "17.1.0-tuxcare.2",
      "purl": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0562e434-829d-5060-89e8-d6875b71a333",
      "id": "CVE-2017-16009",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-16009 is fixed in version 17.1.0-tuxcare.2 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83fb983a-649b-52e3-927e-629ccad4daff",
      "id": "CVE-2025-59052",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.1.0-tuxcare.2 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35f4867b-a09f-563e-8606-6514ba81b8f4",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.1.0-tuxcare.2 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1eeb2626-efb0-5734-b219-99fdd1b03402",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 17.1.0-tuxcare.2 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:804fb239-a0c8-5265-8f03-c9d197be60c2",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.1.0-tuxcare.2 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3874ce05-f18f-582d-b15b-5963ba63f023",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.1.0-tuxcare.2 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5adfdb25-f443-5e68-8401-f2fcdb06bb5a",
      "id": "CVE-2026-32635",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.1.0-tuxcare.2 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe6f09b8-58f1-53d5-925d-cc86f3c88df5",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 17.1.0-tuxcare.2 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e01e574c-63ba-516e-b05b-0eb6fdec97dc",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.1.0-tuxcare.2 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bee141c-31e2-5909-bed3-9c78c89e6126",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.1.0-tuxcare.2 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfd01928-4998-53c1-ad2c-c83aabccb3da",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.1.0-tuxcare.2 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a7c3abc-cc98-5876-ba07-3474e3c7442d",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.1.0-tuxcare.2 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b8d8e75-2432-59d0-9e2a-b9d1da2fd5ae",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.1.0-tuxcare.2 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f53ebe68-fc58-517c-9006-8908c0413242",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.1.0-tuxcare.2 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65c35064-73b8-56e0-b98b-5cbdf64e924f",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.1.0-tuxcare.2 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb1856ab-90d4-55db-a56a-bc6d33b78460",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50556 does not affect version 17.1.0-tuxcare.2 of @angular/bazel. not_affected \u2014 The Angular repository source code is NOT affected by CVE-2026-50556. The vulnerability exists in the external domino dependency (lib/NodeUtils.js), not in Angular's source code. TuxCare's own patch documentation explicitly states: 'DEPENDENCY fix, NOT Angular source' and 'domino is external/runtime (not bundled)'. Angular's code only imports and calls domino's API but does not contain domino's..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce1fcb92-4ae1-5b05-bd77-29c9f918a4be",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.1.0-tuxcare.2 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90ed8cb9-6c3d-5bfa-9a74-f1599de79fc8",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.1.0-tuxcare.2 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:993bc7df-7369-545a-8d83-2eb48b333ba5",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.1.0-tuxcare.2 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d933464-b80c-5b27-8efa-c4490e7d02d8",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 17.1.0-tuxcare.2 of @angular/bazel. not_affected \u2014 Angular v17.1.0 does not have the TwoWayProperty IR operation that is the subject of CVE-2026-54265. Two-way bindings are desugared into separate property and event bindings before template pipeline processing, with the property half using the same parsePropertyBinding() code path as one-way property bindings, which are properly sanitized."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d660cbd-3dab-5ac8-8a65-dab2f180ec45",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.1.0-tuxcare.2 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:395a29ba-dc72-54fb-87a8-bc8662de1a51",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.1.0-tuxcare.2 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db500718-97a0-507e-996d-e07518aea0cd",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.1.0-tuxcare.2 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.2"
    }
  ]
}