{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b9894eff-54fb-5ac7-895b-382bf9b9f32d",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/platform-server",
      "purl": "pkg:npm/%40angular/platform-server@7.2.16-tuxcare.4",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/platform-server@7.2.16-tuxcare.4",
      "version": "7.2.16-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@7.2.16-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:bc954a2d-1a5f-5d66-9cb3-72f105bd4cf9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 7.2.16-tuxcare.4 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@7.2.16-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f11562f3-6a86-52b2-bd17-88839dfc2365",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 7.2.16-tuxcare.4 of @angular/platform-server, and is fixed in 7.2.16-tuxcare.10."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@7.2.16-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ccb348a3-3872-5f6c-842d-4596ad27e6f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 7.2.16-tuxcare.4 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@7.2.16-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a06dfec9-55ad-5bea-ae79-92dceef4d0ef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 7.2.16-tuxcare.4 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@7.2.16-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0a81260a-82e6-5fdd-9cd5-7ac2d39e9f55",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 7.2.16-tuxcare.4 of @angular/platform-server, and is fixed in 7.2.16-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@7.2.16-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:66428f67-0fe3-5198-9e3e-f9b0d0942a1c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 7.2.16-tuxcare.4 of @angular/platform-server, and is fixed in 7.2.16-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@7.2.16-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6eb98825-460b-5ac8-992d-1ced9cb61656",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 7.2.16-tuxcare.4 of @angular/platform-server, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@7.2.16-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:49c75ea7-0727-5c13-8bd6-92dd3c82ec9d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 7.2.16-tuxcare.4 of @angular/platform-server, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@7.2.16-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8eb4c390-e01d-542f-976c-a5d8fc2ce2c1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 7.2.16-tuxcare.4 of @angular/platform-server, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@7.2.16-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f9a1e9f6-a23d-50ee-ab8b-30fcadeabb3a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 7.2.16-tuxcare.4 of @angular/platform-server, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@7.2.16-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:964ba994-c485-5f53-ad4d-4947b408054e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 7.2.16-tuxcare.4 of @angular/platform-server, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@7.2.16-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1c81e2e8-c0ed-5dee-9867-cb1d3a4f6d72",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 7.2.16-tuxcare.4 of @angular/platform-server, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@7.2.16-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a1e32c37-56b3-5d73-8996-840cbed57574",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 7.2.16-tuxcare.4 of @angular/platform-server, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@7.2.16-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:abf41000-81bb-5618-9e3d-84b0a4a179a3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 7.2.16-tuxcare.4 of @angular/platform-server, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@7.2.16-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:566a23ea-945a-5212-8fa2-88ae7bb41dda",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 7.2.16-tuxcare.4 of @angular/platform-server, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@7.2.16-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9c015419-3ee6-53e0-90c2-714b979e4863",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 7.2.16-tuxcare.4 of @angular/platform-server, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@7.2.16-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1fd8946e-446f-5054-b257-51ccb36714ca",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 7.2.16-tuxcare.4 of @angular/platform-server, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@7.2.16-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7a7968d3-df01-5afa-ad05-debad9b24865",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 7.2.16-tuxcare.4 of @angular/platform-server, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@7.2.16-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ffdb5308-d569-5e71-bdfd-ef72e2b0fcc9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 7.2.16-tuxcare.4 of @angular/platform-server, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@7.2.16-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7c153aa3-2b97-50e2-ba7d-8baee6a7fe81",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 7.2.16-tuxcare.4 of @angular/platform-server, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@7.2.16-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0cfa7dbe-e2dd-557b-a93e-7a7e742a91f5",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 7.2.16-tuxcare.4 of @angular/platform-server. not_affected \u2014 Angular 7.2.16 is not affected by CVE-2026-68945. The vulnerability concerns HttpTransferCache's cache key generation logic that treats repeated HTTP parameters (`?role=user&role=admin`) and comma-separated values (`?role=user,admin`) as identical, causing cache key collisions. However, the HttpTransferCache feature does not exist in version 7.2.16\u2014it was introduced in Angular v16. While v7.2.1...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@7.2.16-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3259d71b-2ea6-5eb6-8dba-f247bea8fde1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 7.2.16-tuxcare.4 of @angular/platform-server, and is fixed in 7.2.16-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@7.2.16-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:cb06a82c-37e7-5d88-aeb2-7433915fb5e4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 7.2.16-tuxcare.4 of @angular/platform-server, and is fixed in 7.2.16-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@7.2.16-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:2761be7f-8201-5d43-8c0d-1d70a37cd9bc",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 7.2.16-tuxcare.4 of @angular/platform-server. not_affected \u2014 Angular 7.2.16 is not affected by CVE-2026-88056. The vulnerability requires a String.prototype.trim() call on URLs during server-side rendering that strips Unicode whitespace characters, converting same-origin relative URLs into cross-origin protocol-relative URLs. This vulnerable code pattern does not exist in Angular 7.2.16. The CVE describes a vulnerability introduced in later Angular versi...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@7.2.16-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:58eb1a07-40ab-559e-9eea-f022c143cc9f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88057 does not affect version 7.2.16-tuxcare.4 of @angular/platform-server. not_affected \u2014 Angular 7.2.16 is not affected by CVE-2026-88057. The vulnerability exists in the Ivy compiler's template pipeline (introduced in Angular 9+), which does not exist in this version. Angular 7.2.16 uses View Engine, where the SecurityContext determination for directive host bindings correctly uses the concrete host element name (`element.name`) rather than the directive's selector. The exploitati...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@7.2.16-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:76da4f7f-024c-54e7-8d9e-c65aa42a0aab",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 7.2.16-tuxcare.4 of @angular/platform-server. not_affected \u2014 Angular 7.2.16 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, withRequestsMadeViaParent(), and client hydration features that were introduced in Angular v16+. Angular 7.2.16 predates these features by approximately 7 major versions. The codebase contains only legacy TransferState (manual key-value store) and NgModule-based HttpClient (no hierarchical delegation...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@7.2.16-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ccabfd47-a168-59e7-b132-e1cf9a260543",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 7.2.16-tuxcare.4 of @angular/platform-server."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-server@7.2.16-tuxcare.4"
    }
  ]
}