{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:afbfa1a1-ae6f-50f7-8042-927f79d44faf",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.2",
      "type": "library",
      "name": "@angular/compiler-cli",
      "version": "17.1.0-tuxcare.2",
      "purl": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:8082954b-cddd-5b74-9e48-4746970d7131",
      "id": "CVE-2017-16009",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-16009 is fixed in version 17.1.0-tuxcare.2 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b475ec1-f10d-546b-940a-bf1382d2ed53",
      "id": "CVE-2025-59052",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.1.0-tuxcare.2 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ced8cae-49ab-5905-9404-43ce24468909",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.1.0-tuxcare.2 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efaddbd6-f5ca-57f9-8e64-3ff990b4541f",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 17.1.0-tuxcare.2 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f80d1288-ea7f-5705-be36-e2ced3621a19",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.1.0-tuxcare.2 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b69aceb-278e-5c8b-bab0-55c15169f7ef",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.1.0-tuxcare.2 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4168b3c-9f35-5759-8dd3-b6ff0fb0f7c6",
      "id": "CVE-2026-32635",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.1.0-tuxcare.2 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e880f0e-8e87-554a-b044-4ecccdbdfe2c",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 17.1.0-tuxcare.2 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:958524d4-6949-59c1-b8e5-1e37946d8148",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.1.0-tuxcare.2 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb9ad1b0-94ab-5fc6-bf9a-342923cf5cbf",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.1.0-tuxcare.2 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26f78a2b-3773-51a9-a91b-c34097dc18b2",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.1.0-tuxcare.2 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:471a4cd1-35de-51ae-b64d-72056088700b",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.1.0-tuxcare.2 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e497ebbf-481b-5e93-aeb0-3df9c9656c67",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.1.0-tuxcare.2 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd255924-5451-5216-8232-8bbc7b0fa3f6",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.1.0-tuxcare.2 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bdb977e-14b2-55f6-b37b-381ac1c3adb9",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.1.0-tuxcare.2 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23462ca1-9481-5b51-b1c6-62a77a8d454b",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50556 does not affect version 17.1.0-tuxcare.2 of @angular/compiler-cli. not_affected \u2014 The Angular repository source code is NOT affected by CVE-2026-50556. The vulnerability exists in the external domino dependency (lib/NodeUtils.js), not in Angular's source code. TuxCare's own patch documentation explicitly states: 'DEPENDENCY fix, NOT Angular source' and 'domino is external/runtime (not bundled)'. Angular's code only imports and calls domino's API but does not contain domino's..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:182198df-08a3-5582-bcf9-32b1530a39f3",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.1.0-tuxcare.2 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dea45dfe-72bf-50ee-8f9f-99edfa16df17",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.1.0-tuxcare.2 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34a2c8f9-a139-5ddf-93b5-57b769db9563",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.1.0-tuxcare.2 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eee3705b-dd15-5e54-93ff-272ac8c00a98",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 17.1.0-tuxcare.2 of @angular/compiler-cli. not_affected \u2014 Angular v17.1.0 does not have the TwoWayProperty IR operation that is the subject of CVE-2026-54265. Two-way bindings are desugared into separate property and event bindings before template pipeline processing, with the property half using the same parsePropertyBinding() code path as one-way property bindings, which are properly sanitized."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d05694ef-530e-5efd-928a-ff340d2795d6",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.1.0-tuxcare.2 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbf2abf1-7af0-5084-88ab-50bc3ba4f563",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.1.0-tuxcare.2 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4eee435-5745-571d-9c2c-a7c74b914f33",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.1.0-tuxcare.2 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.2"
    }
  ]
}