{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f7197fc8-be26-5b0b-b2fa-6aee21057749",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/service-worker",
      "purl": "pkg:npm/%40angular/service-worker@12.2.17",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/service-worker@12.2.17",
      "version": "12.2.17",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:845868ee-6d9e-5bf4-b721-f3839dadcc75",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 12.2.17 of @angular/service-worker, and is fixed in 12.2.17-tuxcare.8."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:d24c1fbb-58b3-5388-a190-befe68c94045",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 12.2.17 of @angular/service-worker, and is fixed in 12.2.17-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:a88bbd2a-eb1c-53f3-bd30-1673e3e3fd70",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 12.2.17 of @angular/service-worker, and is fixed in 12.2.17-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:57546c27-2809-53aa-a0a5-85b785c9afbb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 12.2.17 of @angular/service-worker, and is fixed in 12.2.17-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:75396d92-442c-5111-9569-342970a51a94",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 12.2.17 of @angular/service-worker, and is fixed in 12.2.17-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:3cb2ff6c-3034-5c5b-a049-88e1f94ded2b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 12.2.17 of @angular/service-worker, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:b665edac-0113-57dc-9d2f-31d322fdc8cb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 12.2.17 of @angular/service-worker, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:3e7f90dc-40c6-559f-8ca4-3026b3bb7fec",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 12.2.17 of @angular/service-worker, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:37db2367-1598-545a-8ff4-4665349ce549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 12.2.17 of @angular/service-worker, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:3bc6ad18-3fd0-5ad7-8153-c5849aaad028",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 12.2.17 of @angular/service-worker, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:2562f7c6-e6e2-5dcb-ba70-85d38e691a55",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 12.2.17 of @angular/service-worker, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:9921b9a3-f4a5-50e5-8636-56a7b4facdf1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 12.2.17 of @angular/service-worker, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:961fea08-a180-5a0a-8e91-4356ea2dffc2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 12.2.17 of @angular/service-worker, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:1c45919d-a4a4-5689-9cfa-d2171b83794b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 12.2.17 of @angular/service-worker, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:d886b2b2-026c-57dc-b091-a1c2c64ecb3b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 12.2.17 of @angular/service-worker, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:3c6546c1-6e8b-577f-ba90-7cb4f11ca0e1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 12.2.17 of @angular/service-worker, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:3804033c-4e3d-567e-8208-39998b701207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 12.2.17 of @angular/service-worker, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:5cb1942d-2c9c-5e0e-9a1c-27b3a4548b35",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 12.2.17 of @angular/service-worker, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:028e2b32-4838-53b4-ac72-cef41c24fbf2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 12.2.17 of @angular/service-worker, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:c680be43-b969-5872-94ee-0d99c2eafd79",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 12.2.17 of @angular/service-worker. not_affected \u2014 Angular 12.2.17 does not contain the HttpTransferCache feature affected by CVE-2026-68945. HttpTransferCache, which caches HTTP requests during Server-Side Rendering (SSR), was first introduced in Angular 16.0.0\u2014approximately 4 major versions after the target version. The vulnerability concerns cache-key collision when repeated HTTP parameters are serialized, but since the entire HttpTransferCa...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:58560b4c-99a3-514c-a139-016eae5b2345",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 12.2.17 of @angular/service-worker, and is fixed in 12.2.17-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:dfd54ef8-28a3-5dfd-bd1c-ee8f35265555",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 12.2.17 of @angular/service-worker, and is fixed in 12.2.17-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:e7cd93bc-9777-53f3-80c5-fca1c513a498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88056 affects version 12.2.17 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:d4a6fb5e-cd59-54c6-8eab-f494c75e4f48",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 12.2.17 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:2bcf1df0-76eb-5f8f-a3ff-f4cd16f39248",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 12.2.17 of @angular/service-worker. not_affected \u2014 Angular 12.2.17-tuxcare.9 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, withRequestsMadeViaParent(), and provideClientHydration() features which were introduced in Angular 16.0.0. This version uses the older module-based HttpClientModule system and lacks the entire SSR hydration transfer-cache infrastructure. The vulnerable code pattern described in the CVE do...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:7c564e57-b683-5ce7-a711-4a81f4546e2f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 12.2.17 of @angular/service-worker."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/service-worker@12.2.17"
    }
  ]
}