{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4b6b526f-6af0-5075-89f1-1d2b4da36bb3",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/router",
      "purl": "pkg:npm/%40angular/router@18.2.14-tuxcare.9",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.9",
      "version": "18.2.14-tuxcare.9",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:62e99f50-f04a-5f61-a381-edfd9dd08ae7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.14-tuxcare.9 of @angular/router."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:38c3fd04-397a-5423-86dd-247b2f849835",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.2.14-tuxcare.9 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:08be95b8-f44e-5278-bdd6-8e1f28ba1213",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.2.14-tuxcare.9 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:412ef65b-b284-5e8d-8ed1-26ba10fa77dd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.2.14-tuxcare.9 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:0f490712-857a-57da-bce0-9e00ef34e83e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.2.14-tuxcare.9 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:75c61402-633b-5161-ba46-35a5298dc6d7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 18.2.14-tuxcare.9 of @angular/router, and is fixed in 18.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:71affa03-cb2a-52e0-925a-de90057af9fc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 18.2.14-tuxcare.9 of @angular/router, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:c6ed7039-4eb2-5995-81da-442422d66c59",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 18.2.14-tuxcare.9 of @angular/router, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:71aa30e5-2917-5a5d-94f7-ddee96d4507f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 18.2.14-tuxcare.9 of @angular/router, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:02dedd67-3ada-52a2-8110-6aa80d29b613",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 18.2.14-tuxcare.9 of @angular/router, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:908b5513-1764-582d-a3b2-d3c81c559d04",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 18.2.14-tuxcare.9 of @angular/router, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:b8ac2df9-fb68-522c-b0ae-3315e6494fa0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 18.2.14-tuxcare.9 of @angular/router, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:95247605-3979-5ed4-b7d8-9e60ab70dd8d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 18.2.14-tuxcare.9 of @angular/router, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:f29bb176-7721-59d2-88bc-6a44396a4057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 18.2.14-tuxcare.9 of @angular/router, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:359f1b0d-e0c0-58d2-9885-a342d6fd4ce1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 18.2.14-tuxcare.9 of @angular/router, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:85e4f5f0-ebd9-5b9f-80ce-67ccc9c50bf8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 18.2.14-tuxcare.9 of @angular/router, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:7aa05e30-e876-52f6-bd12-0deed9206e26",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 18.2.14-tuxcare.9 of @angular/router, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:cd77ffa7-6c71-51d2-9a25-0265d5e2d5dd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 18.2.14-tuxcare.9 of @angular/router, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:58eff6b1-721d-581f-9f76-23550859f444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 18.2.14-tuxcare.9 of @angular/router, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:ed27621b-8388-52d7-adda-21bfacdde7eb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 18.2.14-tuxcare.9 of @angular/router, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:34f3f520-2054-5a91-8e3d-d92e82133d4a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 18.2.14-tuxcare.9 of @angular/router, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:ced8ff91-18f4-5907-8911-154ca5f37f6e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 18.2.14-tuxcare.9 of @angular/router, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:aa3131d9-96b2-57f7-8af5-c9bc8b9f2139",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 18.2.14-tuxcare.9 of @angular/router, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:37607503-5a41-531a-864b-39dd3f5624ca",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.2.14-tuxcare.9 of @angular/router. not_affected \u2014 The target version 18.2.14-tuxcare.13 is NOT affected by CVE-2026-88056. The vulnerable code pattern (calling String.prototype.trim() on URL strings before resolution) was never present in this version. The target uses a refactored parseUrl() implementation introduced via commit 49a60f6045 (May 2026) that correctly handles Unicode whitespace by percent-encoding it rather than stripping it, main...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:8810f5f3-480f-5587-bcac-a4c1aa88c935",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 18.2.14-tuxcare.9 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:d1183ea7-1016-5682-8c6a-449bcb69f245",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 18.2.14-tuxcare.9 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:1124069c-5a79-5002-b767-cf0ad737179b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 18.2.14-tuxcare.9 of @angular/router."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.9"
    }
  ]
}