{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b81c0d14-d554-56e3-b930-084b824a8abe",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/router",
      "purl": "pkg:npm/%40angular/router@18.2.14-tuxcare.12",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.12",
      "version": "18.2.14-tuxcare.12",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:05ec8e04-f031-550e-a806-5ad2f3a52a6e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.14-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:15efa290-3702-5f73-b33f-e5a88e1571ba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.2.14-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:686f78ef-8bd4-5829-8938-2977fd0ee8d5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.2.14-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:0aaf4e93-1cc5-5036-aa60-46dbd32a2696",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.2.14-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:760de6a7-0566-5ec1-ae53-ad210fb04641",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.2.14-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:cf605f2a-29af-52e8-bd62-7c02e3e360d4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 18.2.14-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:ee67140d-63e1-5e86-908f-c12c97f06b1f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 18.2.14-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:6a6f3769-78c8-5c6f-bd90-a265754bb45b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 18.2.14-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:2c7eea27-b001-585d-9a5e-1f76b279bdc1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 18.2.14-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:c854af76-bec4-547f-853d-d5c5a11279e9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 18.2.14-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:d34b1c5c-0a8c-53d3-b2d8-ab024c5c82af",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 18.2.14-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:532ca8bf-9184-54a6-831d-848d579a7b9c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 18.2.14-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:93f97eb9-8423-5804-858f-e2fce80e3555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 18.2.14-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:bedf0422-5833-5158-b973-05a39031bca7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 18.2.14-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:fddcdabf-8b58-5515-b19b-927b83f58ab5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 18.2.14-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:743bd19c-7fc9-5a5c-8478-7b5b2793ccf5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 18.2.14-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:48b3dd1c-937f-510d-bf20-f8cc8b21da42",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 18.2.14-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:91123bf9-b548-5b92-a88b-dfcd628bdbbd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 18.2.14-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:706fc989-5d64-52fe-b814-e96128961c26",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 18.2.14-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:fcd7e824-d6d8-5c28-a226-232e680fa02e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 18.2.14-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:200a1fa5-ee21-5af8-b637-e6044399ddaa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 18.2.14-tuxcare.12 of @angular/router, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:3cb64ca0-5e07-5143-b01a-e43de92921bb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 18.2.14-tuxcare.12 of @angular/router, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:3b321c87-8821-5fc2-8f9a-9d5d35bf44d5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 18.2.14-tuxcare.12 of @angular/router, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:56b01bda-9a20-5233-997e-3cc994de52b8",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.2.14-tuxcare.12 of @angular/router. not_affected \u2014 The target version 18.2.14-tuxcare.13 is NOT affected by CVE-2026-88056. The vulnerable code pattern (calling String.prototype.trim() on URL strings before resolution) was never present in this version. The target uses a refactored parseUrl() implementation introduced via commit 49a60f6045 (May 2026) that correctly handles Unicode whitespace by percent-encoding it rather than stripping it, main...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:1b3c836f-43cc-5a80-a4a6-f879632921dd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 18.2.14-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:6659923b-c77f-576a-a6df-f509915f4ad5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 18.2.14-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:24276e4e-8c48-5858-ad45-540da5a8ebac",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 18.2.14-tuxcare.12 of @angular/router."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.12"
    }
  ]
}