{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b079edfb-3671-5af4-81e0-0b88718bee79",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.2",
      "type": "library",
      "name": "@angular/core",
      "version": "17.1.0-tuxcare.2",
      "purl": "pkg:npm/%40angular/core@17.1.0-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:46cf9ecd-437f-5013-bcf4-658971baaec7",
      "id": "CVE-2017-16009",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-16009 is fixed in version 17.1.0-tuxcare.2 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c530ba02-fb7a-5745-9d6b-5ab482e169a3",
      "id": "CVE-2025-59052",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.1.0-tuxcare.2 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e65b0cb-1fde-5284-8d0b-fe8ecd017d72",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.1.0-tuxcare.2 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c71ee0c-3462-52ae-a329-de55681e45d5",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 17.1.0-tuxcare.2 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41433138-d739-5aa4-acc0-bee788f865b3",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.1.0-tuxcare.2 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f90d8ee5-733f-56dd-83e3-a866a2777bd1",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.1.0-tuxcare.2 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f097dee-f945-5783-800e-89532fcbf85a",
      "id": "CVE-2026-32635",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.1.0-tuxcare.2 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d51f7d4-bd6b-5361-af33-6ae38816caa3",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 17.1.0-tuxcare.2 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00bd915e-c14f-5130-8821-d8e097f2e584",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.1.0-tuxcare.2 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd9ada93-dc33-5099-b31e-fe754f60ac15",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.1.0-tuxcare.2 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5791fcc0-5417-5f4a-9bbb-bd5f71a568cb",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.1.0-tuxcare.2 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:240e6e3e-543d-5abc-9dee-b6997121b194",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.1.0-tuxcare.2 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59632974-c819-5941-ae24-89a2b8796043",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.1.0-tuxcare.2 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bae26561-0327-5829-b9c8-9e49eba0aa4e",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.1.0-tuxcare.2 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c63c2a00-e522-5948-9889-33cc5d79b3d6",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.1.0-tuxcare.2 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c300e231-072b-52aa-81e7-fff41ceef939",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50556 does not affect version 17.1.0-tuxcare.2 of @angular/core. not_affected \u2014 The Angular repository source code is NOT affected by CVE-2026-50556. The vulnerability exists in the external domino dependency (lib/NodeUtils.js), not in Angular's source code. TuxCare's own patch documentation explicitly states: 'DEPENDENCY fix, NOT Angular source' and 'domino is external/runtime (not bundled)'. Angular's code only imports and calls domino's API but does not contain domino's..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ffa52da-30f1-5314-bbc4-95a5690f1df6",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.1.0-tuxcare.2 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a13afff-c167-50d7-bcf7-b40bcaec2a62",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.1.0-tuxcare.2 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b380311-3c95-5bf1-b9f5-0271ea1d1382",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.1.0-tuxcare.2 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bca0883-d49e-5ca8-8e28-118856b21505",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 17.1.0-tuxcare.2 of @angular/core. not_affected \u2014 Angular v17.1.0 does not have the TwoWayProperty IR operation that is the subject of CVE-2026-54265. Two-way bindings are desugared into separate property and event bindings before template pipeline processing, with the property half using the same parsePropertyBinding() code path as one-way property bindings, which are properly sanitized."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e3476a6-25dd-5b25-a9a0-2970e6d4bd46",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.1.0-tuxcare.2 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0845d13a-89c6-5b09-adee-4c41b6c7acaa",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.1.0-tuxcare.2 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:347933ec-6ebe-5c5f-9679-b9342e726761",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.1.0-tuxcare.2 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.2"
    }
  ]
}