{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:660aa6fd-5e10-581e-badd-85794b695ae6",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/forms",
      "purl": "pkg:npm/%40angular/forms@12.2.17",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/forms@12.2.17",
      "version": "12.2.17",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:d97dc58e-2c5b-5e3c-8cd6-2c747ff33064",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 12.2.17 of @angular/forms, and is fixed in 12.2.17-tuxcare.8."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:e96649e5-948b-5899-b9e5-9e9df5617e87",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 12.2.17 of @angular/forms, and is fixed in 12.2.17-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:5eb5a1dc-8080-5438-baad-abcb20b10647",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 12.2.17 of @angular/forms, and is fixed in 12.2.17-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:6554f4f7-2f8b-57ea-9f43-5d158f4cf357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 12.2.17 of @angular/forms, and is fixed in 12.2.17-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:24f3e627-f8d3-5420-bb60-b47597f620e6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 12.2.17 of @angular/forms, and is fixed in 12.2.17-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:eacfb091-fcad-5f66-aa88-81b7bae44c4f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 12.2.17 of @angular/forms, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:e95bff76-cd7c-5bab-8b86-af8e225c9478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 12.2.17 of @angular/forms, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:2488cdd9-5e15-5430-b2e6-e23fcd07a740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 12.2.17 of @angular/forms, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:a651dfb1-bc1d-5715-bcf1-6893413aab7b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 12.2.17 of @angular/forms, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:8391087a-e586-528c-a289-9ffcca7dd2d9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 12.2.17 of @angular/forms, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:dbcd5f9d-db47-5952-9f1c-ab00536e8300",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 12.2.17 of @angular/forms, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:4866fe89-53d3-5bbc-a220-40bc9dbbd09f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 12.2.17 of @angular/forms, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:feba4974-f9a6-58da-b492-e21650d76281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 12.2.17 of @angular/forms, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:da797651-0389-5a4d-8e85-30235c2615ef",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 12.2.17 of @angular/forms, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:2e5ff1c4-3e7b-5cfd-a4e8-fb1a070e5d9a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 12.2.17 of @angular/forms, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:a0886e6b-c311-50bd-a225-23c0974ccf1d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 12.2.17 of @angular/forms, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:d504e205-bf23-5a4d-9b11-31d1a4e5411a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 12.2.17 of @angular/forms, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:f77c21af-77ae-54ce-995a-87ebffd677d1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 12.2.17 of @angular/forms, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:15c6f63e-38a2-5f3e-a72a-e0338ed388d5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 12.2.17 of @angular/forms, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:e25e20c3-42d0-5198-adf3-10628effbf33",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 12.2.17 of @angular/forms. not_affected \u2014 Angular 12.2.17 does not contain the HttpTransferCache feature affected by CVE-2026-68945. HttpTransferCache, which caches HTTP requests during Server-Side Rendering (SSR), was first introduced in Angular 16.0.0\u2014approximately 4 major versions after the target version. The vulnerability concerns cache-key collision when repeated HTTP parameters are serialized, but since the entire HttpTransferCa...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:9a2de54b-8776-54bb-b446-85e7d9b4b144",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 12.2.17 of @angular/forms, and is fixed in 12.2.17-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:c196f5c8-c750-56f4-b054-06928c3ab176",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 12.2.17 of @angular/forms, and is fixed in 12.2.17-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:73d4915a-a4c0-5fc4-bc15-a934e073700d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88056 affects version 12.2.17 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:e5ed6d1f-520a-58ad-a695-d77f5d0f8667",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 12.2.17 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:4900e75a-fc1e-53c5-a07c-2dc1280a375f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 12.2.17 of @angular/forms. not_affected \u2014 Angular 12.2.17-tuxcare.9 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, withRequestsMadeViaParent(), and provideClientHydration() features which were introduced in Angular 16.0.0. This version uses the older module-based HttpClientModule system and lacks the entire SSR hydration transfer-cache infrastructure. The vulnerable code pattern described in the CVE do...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:fbb3840f-13b1-59ee-8cc0-cdacb7ecf4ab",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 12.2.17 of @angular/forms."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/forms@12.2.17"
    }
  ]
}