{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f05cd0e3-06f3-5110-b46b-dc3a6da21df9",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/upgrade",
      "purl": "pkg:npm/%40angular/upgrade@12.2.17",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/upgrade@12.2.17",
      "version": "12.2.17",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:339ad1cd-c6be-50a3-afaf-2477f71e85c1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 12.2.17 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.8."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:787ee977-05c9-57d0-836b-e16df122bbd7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 12.2.17 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:57d69936-9971-50f2-a1a6-b17415459769",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 12.2.17 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:13c1d5f7-b199-5e73-9032-456fc6df9585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 12.2.17 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:17c3ca3c-3fd0-5285-8157-170501c57563",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 12.2.17 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:07c0a6a3-ba1e-5bb1-8367-9ecf266fbbc5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 12.2.17 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:3860c254-12c6-5c3e-a346-16a1b77fa838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 12.2.17 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:75b4d57f-2fca-58ff-b294-47b85c10de5d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 12.2.17 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:311801e7-1fd8-5ef1-8bb9-72e4114facb3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 12.2.17 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:65b70629-6123-5bf1-940e-6a00a642ccba",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 12.2.17 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:4289a55a-b04d-5e14-ba84-498061c5c6cf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 12.2.17 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:4a06b427-e2f8-5922-a5e1-c840b5c3eb02",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 12.2.17 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:5913fddd-ab93-50f3-b0b9-a1dd3d003c4d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 12.2.17 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:b4207e50-7850-52d7-aff3-32290d2e88aa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 12.2.17 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:919b0f63-7a0d-5eac-a3a8-c9df2b539fb3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 12.2.17 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:397cb997-0f90-5c6c-aaf6-6f755c60ea5a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 12.2.17 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:7d83e674-c68e-5b45-998e-7f7f7f3f7f57",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 12.2.17 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:46466e43-6c1d-5904-9117-4a809f71dc4c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 12.2.17 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:73186fa0-58e6-5195-a3b3-0c77382c30bc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 12.2.17 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:02a9a5d5-dffb-5fdb-9e99-0e963666da7f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 12.2.17 of @angular/upgrade. not_affected \u2014 Angular 12.2.17 does not contain the HttpTransferCache feature affected by CVE-2026-68945. HttpTransferCache, which caches HTTP requests during Server-Side Rendering (SSR), was first introduced in Angular 16.0.0\u2014approximately 4 major versions after the target version. The vulnerability concerns cache-key collision when repeated HTTP parameters are serialized, but since the entire HttpTransferCa...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:4e89fd95-2b5c-55c8-b0a8-4f72d2f85a73",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 12.2.17 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:f0cf1e1f-bbd2-5cdc-b53b-6fcd23156c4f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 12.2.17 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:21bc6d37-50f6-5c4b-ad02-c5b76f236fb5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88056 affects version 12.2.17 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:f63ce6a8-daed-548d-99fd-3fd56341218e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 12.2.17 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:079eb0a4-046b-500e-b486-bf78e08ec1ad",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 12.2.17 of @angular/upgrade. not_affected \u2014 Angular 12.2.17-tuxcare.9 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, withRequestsMadeViaParent(), and provideClientHydration() features which were introduced in Angular 16.0.0. This version uses the older module-based HttpClientModule system and lacks the entire SSR hydration transfer-cache infrastructure. The vulnerable code pattern described in the CVE do...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:f8ff9f8b-e05b-5d81-9839-9cabd2c80de6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 12.2.17 of @angular/upgrade."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/upgrade@12.2.17"
    }
  ]
}