{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a0da0b30-61b8-5ca6-a85e-53d4fe018898",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/router",
      "purl": "pkg:npm/%40angular/router@18.2.14-tuxcare.8",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.8",
      "version": "18.2.14-tuxcare.8",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:ffe5cded-1c53-5ccf-a05c-361a8271fad9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.14-tuxcare.8 of @angular/router."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6b34b368-153d-52a8-8a87-0b3735176777",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.2.14-tuxcare.8 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:9bd40f9c-9cd3-5beb-88e0-b70891e8b48c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.2.14-tuxcare.8 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:2bfe561f-09cb-58c4-84f2-9488b22c51fe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.2.14-tuxcare.8 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f9cccc38-77a8-5c9d-a379-fdd1e2733fa3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.2.14-tuxcare.8 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:52f48130-432f-5a46-83c1-ca71d6ed713c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 18.2.14-tuxcare.8 of @angular/router, and is fixed in 18.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:0303012d-7cca-5204-8d73-d57e50d1f0fa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 18.2.14-tuxcare.8 of @angular/router, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f284e1a8-4185-5ace-82d3-df4f27e361e9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 18.2.14-tuxcare.8 of @angular/router, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:110c1bc9-7a39-5c4b-bd3e-456795f9072e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 18.2.14-tuxcare.8 of @angular/router, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:ffa68bb5-00e7-5a51-b5b7-beb7a488d235",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 18.2.14-tuxcare.8 of @angular/router, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f9776c0f-9b65-50a6-ae50-fe2ada3ebed7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 18.2.14-tuxcare.8 of @angular/router, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:2b2b4593-86aa-552c-8945-dd288c32d03c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 18.2.14-tuxcare.8 of @angular/router, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:319f4661-cfa4-57f2-9dd4-a8cda50d5c3e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 18.2.14-tuxcare.8 of @angular/router, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:d0265302-74a3-52e1-8293-854085e29198",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 18.2.14-tuxcare.8 of @angular/router, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:31b20ee1-426f-5e37-9c6c-b56eaa2ff582",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 18.2.14-tuxcare.8 of @angular/router, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:b46ac423-b4e0-5fe0-ab5b-7084e58682f3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 18.2.14-tuxcare.8 of @angular/router, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:e1266a97-c175-5003-ab9f-b563f2c8305a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 18.2.14-tuxcare.8 of @angular/router, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:68a125a3-cea1-5a56-b314-79ae6a923b6f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 18.2.14-tuxcare.8 of @angular/router, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:da1e9101-9760-5a34-973c-7d6cf5ee9d44",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 18.2.14-tuxcare.8 of @angular/router, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:ce46a977-357e-5ea5-824c-1ecde328e760",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 18.2.14-tuxcare.8 of @angular/router, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:daf938e0-9f4c-503d-8a26-7195f2b0bcae",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 18.2.14-tuxcare.8 of @angular/router, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:8441a80b-5ea9-53f2-af14-6967e1618a42",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 18.2.14-tuxcare.8 of @angular/router, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:c8ae666d-4a09-5513-ac10-ed5166da0aa1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 18.2.14-tuxcare.8 of @angular/router, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:376db8dd-f317-5c98-a716-62482afc42ce",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.2.14-tuxcare.8 of @angular/router. not_affected \u2014 The target version 18.2.14-tuxcare.13 is NOT affected by CVE-2026-88056. The vulnerable code pattern (calling String.prototype.trim() on URL strings before resolution) was never present in this version. The target uses a refactored parseUrl() implementation introduced via commit 49a60f6045 (May 2026) that correctly handles Unicode whitespace by percent-encoding it rather than stripping it, main...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:34b2490d-29e9-5f0e-823e-3a7b8f5891e2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 18.2.14-tuxcare.8 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:bcb5b7e9-e16d-51fe-8fba-1f904005948a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 18.2.14-tuxcare.8 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:4cc7eab0-1119-5132-93d9-39b5367c139c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 18.2.14-tuxcare.8 of @angular/router."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.8"
    }
  ]
}