{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0c319d32-f3ed-5c56-971a-3cdbf10280a0",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/platform-webworker",
      "purl": "pkg:npm/%40angular/platform-webworker@7.2.16-tuxcare.7",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/platform-webworker@7.2.16-tuxcare.7",
      "version": "7.2.16-tuxcare.7",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.16-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:b2cde8f2-37a4-5580-b942-a86f01c3c6ef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 7.2.16-tuxcare.7 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.16-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:1421f9c0-13dc-50fe-a529-75d44a74a457",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 7.2.16-tuxcare.7 of @angular/platform-webworker, and is fixed in 7.2.16-tuxcare.10."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.16-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:4572658c-49ce-5e87-bf66-680aa952cbdf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 7.2.16-tuxcare.7 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.16-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:64ef8e41-81cf-54dc-8d2f-ac1937c4cdd0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 7.2.16-tuxcare.7 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.16-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:bcaa5faf-754b-57d9-b357-1e0095ceb2bc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 7.2.16-tuxcare.7 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.16-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:6f9078c8-010d-5ed5-8eb7-85c3414db919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 7.2.16-tuxcare.7 of @angular/platform-webworker, and is fixed in 7.2.16-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.16-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:8b943d60-d213-5b2e-9966-6bf7c23aa3c5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 7.2.16-tuxcare.7 of @angular/platform-webworker, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.16-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:cf5577f5-03a2-5a01-ba39-9257320b071e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 7.2.16-tuxcare.7 of @angular/platform-webworker, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.16-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:8d35ae25-0ebf-5359-95a6-7248c0b8203d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 7.2.16-tuxcare.7 of @angular/platform-webworker, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.16-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:5e60a6e6-98ad-580f-b455-e8938e0efb13",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 7.2.16-tuxcare.7 of @angular/platform-webworker, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.16-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:416cf6ef-d9d7-5a21-bb92-14b10f5f079b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 7.2.16-tuxcare.7 of @angular/platform-webworker, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.16-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:266ae1f5-7329-5fce-bbf3-ec46d98e5bf3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 7.2.16-tuxcare.7 of @angular/platform-webworker, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.16-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:2fd5c4f2-1e53-5b9c-aa08-4b7ffb1c1aaa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 7.2.16-tuxcare.7 of @angular/platform-webworker, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.16-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:ce559212-2a4b-5a43-87d7-6f90a76e4836",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 7.2.16-tuxcare.7 of @angular/platform-webworker, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.16-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:ad41ad08-dd8e-59bb-bef8-8dd6c3a8373a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 7.2.16-tuxcare.7 of @angular/platform-webworker, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.16-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:d8bd13dd-8151-57f7-9c03-bfd22eabbc4e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 7.2.16-tuxcare.7 of @angular/platform-webworker, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.16-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:6c5fb5d1-6901-5086-9212-f1af079faaf8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 7.2.16-tuxcare.7 of @angular/platform-webworker, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.16-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:b9328e83-00d5-552d-939b-425b522f80b7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 7.2.16-tuxcare.7 of @angular/platform-webworker, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.16-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:c0cc3810-979a-54e5-b7eb-d47754ea9974",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 7.2.16-tuxcare.7 of @angular/platform-webworker, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.16-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:2cc37b4e-8378-5bdd-83b5-6ec0aafe719c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 7.2.16-tuxcare.7 of @angular/platform-webworker, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.16-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:ef62ef56-3867-51a9-9f19-935db3fa3599",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 7.2.16-tuxcare.7 of @angular/platform-webworker. not_affected \u2014 Angular 7.2.16 is not affected by CVE-2026-68945. The vulnerability concerns HttpTransferCache's cache key generation logic that treats repeated HTTP parameters (`?role=user&role=admin`) and comma-separated values (`?role=user,admin`) as identical, causing cache key collisions. However, the HttpTransferCache feature does not exist in version 7.2.16\u2014it was introduced in Angular v16. While v7.2.1...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.16-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:73f60012-ab95-5383-87db-b50d1f247c15",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 7.2.16-tuxcare.7 of @angular/platform-webworker, and is fixed in 7.2.16-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.16-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:2c63ff11-f564-52a4-aec3-8fe3a1762553",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 7.2.16-tuxcare.7 of @angular/platform-webworker, and is fixed in 7.2.16-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.16-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:018ef883-635e-5d9c-b79d-fdf47e123d66",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 7.2.16-tuxcare.7 of @angular/platform-webworker. not_affected \u2014 Angular 7.2.16 is not affected by CVE-2026-88056. The vulnerability requires a String.prototype.trim() call on URLs during server-side rendering that strips Unicode whitespace characters, converting same-origin relative URLs into cross-origin protocol-relative URLs. This vulnerable code pattern does not exist in Angular 7.2.16. The CVE describes a vulnerability introduced in later Angular versi...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.16-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:4f229283-4c65-52d8-a643-cd8557ab2774",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88057 does not affect version 7.2.16-tuxcare.7 of @angular/platform-webworker. not_affected \u2014 Angular 7.2.16 is not affected by CVE-2026-88057. The vulnerability exists in the Ivy compiler's template pipeline (introduced in Angular 9+), which does not exist in this version. Angular 7.2.16 uses View Engine, where the SecurityContext determination for directive host bindings correctly uses the concrete host element name (`element.name`) rather than the directive's selector. The exploitati...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.16-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:c8bb5a20-6b37-5abc-bd25-c46ecea3bd43",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 7.2.16-tuxcare.7 of @angular/platform-webworker. not_affected \u2014 Angular 7.2.16 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, withRequestsMadeViaParent(), and client hydration features that were introduced in Angular v16+. Angular 7.2.16 predates these features by approximately 7 major versions. The codebase contains only legacy TransferState (manual key-value store) and NgModule-based HttpClient (no hierarchical delegation...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.16-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:e7d4c0b0-3546-5db4-94d8-086e58fe98a8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 7.2.16-tuxcare.7 of @angular/platform-webworker."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-webworker@7.2.16-tuxcare.7"
    }
  ]
}