{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:84267ebb-d3c4-5ddd-999f-3ec72295e6c1",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/service-worker@18.2.12-tuxcare.3",
      "type": "library",
      "name": "@angular/service-worker",
      "version": "18.2.12-tuxcare.3",
      "purl": "pkg:npm/%40angular/service-worker@18.2.12-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:1e2ffb4c-bafa-5941-9513-afb0314bcb48",
      "id": "CVE-2025-59052",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 18.2.12-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6c1baf0-3b49-5f5c-9671-5d933cf6713c",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.12-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0455abe-ed29-5428-ae01-a2417066c485",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.2.12-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8efa1134-c9df-58d7-a317-6327d2fa1172",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.2.12-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16be1a56-12af-5beb-b351-c3db69480eda",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.2.12-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a9a1a79-ccac-51c8-890a-f0f7c408b1be",
      "id": "CVE-2026-32635",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.2.12-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa914971-a263-59dc-9dd6-7ba80bb04160",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 18.2.12-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f167873c-38c6-5aaa-9c0a-b224360fad13",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 18.2.12-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d463022-3e94-540a-8351-43e4fb6a8903",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 18.2.12-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:344a179f-2415-53b0-82d6-5dfba240adf8",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 18.2.12-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b579b01-c7f9-5330-a7c1-9085827dfca8",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 18.2.12-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7da0037-0cd1-504c-a3fb-f1ee4198e718",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 18.2.12-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82b93db7-9a31-5686-9c84-89034227b074",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 18.2.12-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5c7f682-a9ba-5b47-b2e6-57ec973bfde7",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50555 does not affect version 18.2.12-tuxcare.3 of @angular/service-worker. already_fixed \u2014 CVE-2026-50555 fix is already present in the target repository. The vulnerability concerns XSS in domino's noscript element serialization. The fix (escaping matching closing tags and adding NOSCRIPT to raw-text element handling) exists as a patch file that is automatically applied during yarn install via patch-package."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a987a65f-9faf-51bc-972c-6783256794f9",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50556 does not affect version 18.2.12-tuxcare.3 of @angular/service-worker. already_fixed \u2014 CVE-2026-50556 (XSS via <noscript> raw-text serialization in domino) has been fixed. The target repository contains a committed patch file (tools/esm-interop/patches/npm/domino+2.1.6.patch) that applies the complete fix to the domino dependency. The patch adds NOSCRIPT to the hasRawContent set and removes the conditional _scripting_enabled check, matching the upstream fix exactly. This patch is..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6231ed9d-1645-5aae-8726-cf11781cd3f8",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 18.2.12-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a229bc7-48bf-544b-9551-b8aa03053cb2",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 18.2.12-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34c34b00-b864-5460-8b76-41c194668fe5",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 18.2.12-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f893f4c-5a39-54f7-9931-efb34a661ec6",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 18.2.12-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f41884a5-b98f-56da-8150-983b8958635d",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 18.2.12-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d22cde3-4d24-5f9e-a3e0-7e1a148c035a",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 18.2.12-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.12-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c67c1b1-b664-5e6d-9996-a6d829173e73",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 18.2.12-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.12-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/service-worker@18.2.12-tuxcare.3"
    }
  ]
}