{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a32d436f-0279-59a3-9585-929008c14e5f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.3",
      "type": "library",
      "name": "@angular/benchpress",
      "version": "17.1.0-tuxcare.3",
      "purl": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:561eebf2-edce-5f1c-be64-dec509a0aff9",
      "id": "CVE-2017-16009",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-16009 is fixed in version 17.1.0-tuxcare.3 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b371ec7-e2db-5067-937a-d3919a56eaf1",
      "id": "CVE-2025-59052",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.1.0-tuxcare.3 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdfcfe11-98f0-5330-99d1-590be6d4aa65",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.1.0-tuxcare.3 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80d5c954-6f0e-53c6-81c8-eaf725a4deae",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.1.0-tuxcare.3 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4e900d2-4ece-51be-af76-9a3658b41dbb",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.1.0-tuxcare.3 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a2705ae-ae34-5afe-87a4-ab495abf3d30",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.1.0-tuxcare.3 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ec5cd4a-c426-5334-8ab6-ec346a813493",
      "id": "CVE-2026-32635",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.1.0-tuxcare.3 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd9efad1-adae-5026-9959-5a2ef9e0cc84",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 17.1.0-tuxcare.3 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33c46f2d-ca3f-598b-8e05-148882503677",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.1.0-tuxcare.3 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58c65d26-16f7-56cc-91e6-0ab3c6ca760a",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.1.0-tuxcare.3 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0429c463-17a2-5782-8412-e2478d8f8660",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.1.0-tuxcare.3 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebb48011-1e3a-5082-906d-151d56178bc5",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.1.0-tuxcare.3 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb618e9d-7b49-560e-9f78-d0512c62cc3d",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.1.0-tuxcare.3 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3474a39-d6f1-5ecf-9036-761e9c310996",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.1.0-tuxcare.3 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d4a1fbe-94ef-5674-a41b-6440234920c8",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.1.0-tuxcare.3 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24ae2389-55d2-5b2e-ab91-95c14a57379b",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50556 does not affect version 17.1.0-tuxcare.3 of @angular/benchpress. not_affected \u2014 The Angular repository source code is NOT affected by CVE-2026-50556. The vulnerability exists in the external domino dependency (lib/NodeUtils.js), not in Angular's source code. TuxCare's own patch documentation explicitly states: 'DEPENDENCY fix, NOT Angular source' and 'domino is external/runtime (not bundled)'. Angular's code only imports and calls domino's API but does not contain domino's..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5ec8011-78bf-5f4c-ae8c-ab25bf93d77f",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.1.0-tuxcare.3 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:709d0231-f3a2-5dda-b850-354b098afe54",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.1.0-tuxcare.3 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b43e4329-a2e4-5900-9041-b15cc7807c52",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.1.0-tuxcare.3 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbb93119-54b0-5e40-a5fc-6779f6af5da0",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 17.1.0-tuxcare.3 of @angular/benchpress. not_affected \u2014 Angular v17.1.0 does not have the TwoWayProperty IR operation that is the subject of CVE-2026-54265. Two-way bindings are desugared into separate property and event bindings before template pipeline processing, with the property half using the same parsePropertyBinding() code path as one-way property bindings, which are properly sanitized."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9030d0ea-78a0-5ef5-948d-9d90a2ef907b",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.1.0-tuxcare.3 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8eaa15c0-7d5d-5825-9e40-94deaaebc4ca",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.1.0-tuxcare.3 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:436b519b-049d-555e-abba-6aa762009980",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.1.0-tuxcare.3 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.3"
    }
  ]
}