{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:956d2303-3b7b-59c6-a64a-4fa6ecb3a633",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/compiler@18.1.2-tuxcare.2",
      "type": "library",
      "name": "@angular/compiler",
      "version": "18.1.2-tuxcare.2",
      "purl": "pkg:npm/%40angular/compiler@18.1.2-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:403f363c-1f52-5b0d-b24e-dfd59666dc40",
      "id": "CVE-2025-59052",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 18.1.2-tuxcare.2 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.1.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e805841c-3bf9-5ab7-be89-465bb7a78276",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.1.2-tuxcare.2 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.1.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:caedf98f-70fc-51ec-9343-21d63d18863d",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 18.1.2-tuxcare.2 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.1.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0eb06666-b770-5171-8c4c-74bdcbca5f34",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.1.2-tuxcare.2 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.1.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92144d53-2bbf-5779-947d-1abe8bd77922",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.1.2-tuxcare.2 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.1.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba9cf705-8c9e-598c-96ae-912af5a464f6",
      "id": "CVE-2026-32635",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.1.2-tuxcare.2 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.1.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dec85e6b-43c3-50d2-80ae-83a5515f11b4",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 18.1.2-tuxcare.2 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.1.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0f3b37c-df78-5097-b497-40a69ac3cfa4",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 18.1.2-tuxcare.2 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.1.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:559dde7d-8f68-5a76-8e04-09a056f8c901",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 18.1.2-tuxcare.2 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.1.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf3f6719-8089-5aa7-a5a9-c765124d2fbc",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 18.1.2-tuxcare.2 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.1.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a70b9584-4876-5298-8bee-2272f11042a0",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 18.1.2-tuxcare.2 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.1.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b00d47d6-aa46-5ff2-916c-1d3738d3b018",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 18.1.2-tuxcare.2 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.1.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d70416b3-e419-58bb-90a7-2306aefb6391",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 18.1.2-tuxcare.2 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.1.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61c99da1-79c9-537f-a510-f894b678d446",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50555 does not affect version 18.1.2-tuxcare.2 of @angular/compiler. already_fixed \u2014 The target Angular 18.1.2 repository has already been patched for this vulnerability. TuxCare commit 32991dd728 'fix all CVEs' added a cumulative domino patch that fixes both the NOSCRIPT XSS vulnerability (CVE-2026-50556, corresponding to the provided patch f74cccd) and the astral Unicode index bug (CVE-2026-50555). The patch is applied automatically to the domino dependency via patch-package ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.1.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcde924d-ffcb-5841-8de5-24c54f42dc65",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50556 does not affect version 18.1.2-tuxcare.2 of @angular/compiler. already_fixed \u2014 CVE-2026-50556 (XSS via noscript raw-text serialization in domino) has been fixed in this Angular repository. The fix is present in tools/esm-interop/patches/npm/domino+2.1.6.patch and is automatically applied to the domino dependency during installation via the postinstall script. The patch was added by TuxCare in commit 32991dd728 on 2026-07-01."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.1.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47738452-dde2-5db0-8d44-89566864c450",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 18.1.2-tuxcare.2 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.1.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c287491-42ba-5865-961f-0a7fdf8da58f",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 18.1.2-tuxcare.2 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.1.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4de5c782-5a3a-559d-bf83-a886d33b0182",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 18.1.2-tuxcare.2 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.1.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d683c39c-a05c-528e-af38-e32253baf024",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 18.1.2-tuxcare.2 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.1.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93347c8c-f652-5eca-b887-773150076d94",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 18.1.2-tuxcare.2 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.1.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e42cdb18-d12e-5381-a306-099de83a87fa",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 18.1.2-tuxcare.2 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.1.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:843b0a59-a827-5435-a1dd-05c32d6af85c",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 18.1.2-tuxcare.2 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.1.2-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler@18.1.2-tuxcare.2"
    }
  ]
}