{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:cbc26035-85d8-56e9-b0b7-18a148446f90",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/router",
      "purl": "pkg:npm/%40angular/router@16.2.12-tuxcare.6",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/router@16.2.12-tuxcare.6",
      "version": "16.2.12-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:cba21561-0c29-56ab-a1e5-b5ea6c5aa243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 16.2.12-tuxcare.6 of @angular/router."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0ee46318-e8f8-502a-9ffb-a5e4cedda3e9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.12-tuxcare.6 of @angular/router."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:fd34a627-c4eb-5f41-a8b9-110a16ce238d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 16.2.12-tuxcare.6 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:309906cf-488d-5ded-afb8-0537a120b9a9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 16.2.12-tuxcare.6 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:441fd633-a3d0-5b42-b6e7-52a14de08c9e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 16.2.12-tuxcare.6 of @angular/router, and is fixed in 16.2.12-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c44fee44-a541-5ee5-8497-195b7c33306a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 16.2.12-tuxcare.6 of @angular/router, and is fixed in 16.2.12-tuxcare.10."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7a7a1aba-cd0c-54d3-99c2-bb19a79038e8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 16.2.12-tuxcare.6 of @angular/router, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b6d70a87-7047-5ce2-8ae0-fd754e958e96",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 16.2.12-tuxcare.6 of @angular/router, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d74242ef-0b11-5b21-8330-09a002a51ead",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 16.2.12-tuxcare.6 of @angular/router, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:96c22680-6c2d-5814-b687-dd09fa45dd59",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 16.2.12-tuxcare.6 of @angular/router, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8827509c-1f6c-5cf9-8e7e-226def0fcf57",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 16.2.12-tuxcare.6 of @angular/router, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e9bf6bfd-1170-5cd5-98b2-871378c12a4d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 16.2.12-tuxcare.6 of @angular/router, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:174b2495-64bb-5bae-b167-68d2d71277d5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 16.2.12-tuxcare.6 of @angular/router, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f669930b-d29f-5769-b917-efb4e41d0f21",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 16.2.12-tuxcare.6 of @angular/router, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5c73dc08-b49f-51ff-bf3f-bcef69c48853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 16.2.12-tuxcare.6 of @angular/router, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e0d04333-130b-5d00-9a35-03c03b24db8b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 16.2.12-tuxcare.6 of @angular/router, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2bce3912-e103-589b-9448-26538a4ac58e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 16.2.12-tuxcare.6 of @angular/router, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:bfd43894-7cf3-5059-8b92-60620abf1fd0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 16.2.12-tuxcare.6 of @angular/router, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b9a097ac-866f-5978-82b7-eca290451f23",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 16.2.12-tuxcare.6 of @angular/router, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:412f8dbe-a0fe-5c83-89ed-972243bab723",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 16.2.12-tuxcare.6 of @angular/router, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:860aa11e-4ecd-576f-9f72-f0286d3aded3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 16.2.12-tuxcare.6 of @angular/router, and is fixed in 16.2.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f9a3d337-353f-527b-ba59-2175b64cc054",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 16.2.12-tuxcare.6 of @angular/router, and is fixed in 16.2.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e027ab1b-36dd-547d-90b0-43fd09e95895",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 16.2.12-tuxcare.6 of @angular/router, and is fixed in 16.2.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f600840b-c251-567c-b8ad-7f7daf28a9a6",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.12-tuxcare.6 of @angular/router. not_affected \u2014 CVE-2026-88056 affects Angular versions 20.3.x, 21.2.x, and 22.x where a refactored URL parsing utility added String.prototype.trim() that strips Unicode whitespace, enabling SSRF bypasses. The target (Angular 16.2.12-tuxcare.12) is based on Angular 16.2.x architecture, which predates the vulnerable code pattern entirely. TuxCare created url.ts fresh on June 24, 2026 for CVE-2026-50168, modelin...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:229ac16c-0759-577b-a9a8-4f5f0bc32e63",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 16.2.12-tuxcare.6 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8f4e9274-15f7-5865-8aef-178339da9306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 16.2.12-tuxcare.6 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0fd819a7-0c27-50c9-bd32-3dbc9adb305a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 16.2.12-tuxcare.6 of @angular/router."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/router@16.2.12-tuxcare.6"
    }
  ]
}