{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b2e7a488-b38e-5a15-a7ad-9d772760fee5",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/bazel",
      "purl": "pkg:npm/%40angular/bazel@7.2.16-tuxcare.2",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/bazel@7.2.16-tuxcare.2",
      "version": "7.2.16-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f4014312-7568-56b4-89a4-36ce462077aa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-4231 affects version 7.2.16-tuxcare.2 of @angular/bazel, and is fixed in 7.2.16-tuxcare.4."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9310968d-80ec-5630-afb2-5429780d7a5b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 7.2.16-tuxcare.2 of @angular/bazel, and is fixed in 7.2.16-tuxcare.10."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2b16fafc-5dae-5f4b-8381-f9c85a5f87ac",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 7.2.16-tuxcare.2 of @angular/bazel, and is fixed in 7.2.16-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c7ed06d9-666d-5f7a-81ac-5bc06eaf3420",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 7.2.16-tuxcare.2 of @angular/bazel, and is fixed in 7.2.16-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5656411f-7416-5823-ad83-2f1a2e5fefe5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 7.2.16-tuxcare.2 of @angular/bazel, and is fixed in 7.2.16-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e52fe0c9-652c-54d4-9911-8a3872b6cdfc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 7.2.16-tuxcare.2 of @angular/bazel, and is fixed in 7.2.16-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9ad01c49-81c5-5bf8-9d07-b6bf9e83b92d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 7.2.16-tuxcare.2 of @angular/bazel, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2cbd7078-95cc-5d2d-b3d0-1c5aabb1d40a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 7.2.16-tuxcare.2 of @angular/bazel, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1bc9ea79-19e7-59f6-8dc1-9588a1f3e77f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 7.2.16-tuxcare.2 of @angular/bazel, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:992033fb-225d-55bf-a364-1a9cf71ddf28",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 7.2.16-tuxcare.2 of @angular/bazel, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:84165dd6-64c7-5952-9e60-0765f54ac3d2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 7.2.16-tuxcare.2 of @angular/bazel, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6b6bcb8b-b6e5-5a62-beaa-2117552ea38a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 7.2.16-tuxcare.2 of @angular/bazel, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:35582f38-e78e-57c5-ace3-a8a527cbd49f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 7.2.16-tuxcare.2 of @angular/bazel, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:331d72ec-d59b-52a5-9273-1c2d35b6b0c7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 7.2.16-tuxcare.2 of @angular/bazel, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ce96649e-2bab-5088-acb2-e4501b0e3794",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 7.2.16-tuxcare.2 of @angular/bazel, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:37adf156-d970-5bd1-8c74-d061cd35fa8b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 7.2.16-tuxcare.2 of @angular/bazel, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:45af9595-712f-5c2c-8173-4c72d1a6e5ae",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 7.2.16-tuxcare.2 of @angular/bazel, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b86f32cc-c417-597b-8ac0-2788b9bc3e7c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 7.2.16-tuxcare.2 of @angular/bazel, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0a322a02-64b2-5f4d-9319-17e08af792c8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 7.2.16-tuxcare.2 of @angular/bazel, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:998bf39f-b7a0-59fd-8515-f4033735f45d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 7.2.16-tuxcare.2 of @angular/bazel, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1982f9b7-0b09-5542-82b4-ca182fec8aa0",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 7.2.16-tuxcare.2 of @angular/bazel. not_affected \u2014 Angular 7.2.16 is not affected by CVE-2026-68945. The vulnerability concerns HttpTransferCache's cache key generation logic that treats repeated HTTP parameters (`?role=user&role=admin`) and comma-separated values (`?role=user,admin`) as identical, causing cache key collisions. However, the HttpTransferCache feature does not exist in version 7.2.16\u2014it was introduced in Angular v16. While v7.2.1...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a8ee4d88-2675-5439-9ec1-852790004de8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 7.2.16-tuxcare.2 of @angular/bazel, and is fixed in 7.2.16-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1d7e706b-3811-564d-b57c-7278f42dad4f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 7.2.16-tuxcare.2 of @angular/bazel, and is fixed in 7.2.16-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b6e69aeb-1c68-5214-babe-0a69019156ec",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 7.2.16-tuxcare.2 of @angular/bazel. not_affected \u2014 Angular 7.2.16 is not affected by CVE-2026-88056. The vulnerability requires a String.prototype.trim() call on URLs during server-side rendering that strips Unicode whitespace characters, converting same-origin relative URLs into cross-origin protocol-relative URLs. This vulnerable code pattern does not exist in Angular 7.2.16. The CVE describes a vulnerability introduced in later Angular versi...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c24c0fa5-17f8-55f5-963e-cc07e016d106",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88057 does not affect version 7.2.16-tuxcare.2 of @angular/bazel. not_affected \u2014 Angular 7.2.16 is not affected by CVE-2026-88057. The vulnerability exists in the Ivy compiler's template pipeline (introduced in Angular 9+), which does not exist in this version. Angular 7.2.16 uses View Engine, where the SecurityContext determination for directive host bindings correctly uses the concrete host element name (`element.name`) rather than the directive's selector. The exploitati...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:864c5fbb-62a8-5052-b101-d98a63f54020",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 7.2.16-tuxcare.2 of @angular/bazel. not_affected \u2014 Angular 7.2.16 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, withRequestsMadeViaParent(), and client hydration features that were introduced in Angular v16+. Angular 7.2.16 predates these features by approximately 7 major versions. The codebase contains only legacy TransferState (manual key-value store) and NgModule-based HttpClient (no hierarchical delegation...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:be3b7aa2-88ea-5018-83d3-e8d88008c01f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 7.2.16-tuxcare.2 of @angular/bazel."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/bazel@7.2.16-tuxcare.2"
    }
  ]
}