{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9b803594-45c0-5fb9-bfc1-34e8a727e786",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/router",
      "purl": "pkg:npm/%40angular/router@7.2.0-tuxcare.1",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.1",
      "version": "7.2.0-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:18478917-2eca-5ff1-b189-7f4799f08294",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 7.2.0-tuxcare.1 of @angular/router."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4a084874-af0b-5289-9112-fa611dd53022",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 7.2.0-tuxcare.1 of @angular/router, and is fixed in 7.2.0-tuxcare.2."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7ffcf308-6f53-5605-8a39-cc1dcf4e4f79",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 7.2.0-tuxcare.1 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6c2ad2dd-a039-5383-8fbc-d6f8529f6bb0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 7.2.0-tuxcare.1 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4dc41c59-7b5b-50d6-830c-abe2fcec59eb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 7.2.0-tuxcare.1 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:203970c2-a44d-5830-8c15-62352217281e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 7.2.0-tuxcare.1 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b04b965b-0265-5f5e-914c-3544484b380f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 7.2.0-tuxcare.1 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1e4f7a5a-96f6-5a3b-9bb3-7e8b5a7bbd0e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 7.2.0-tuxcare.1 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3b8b6a64-f233-57e7-a830-21111acc1594",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 7.2.0-tuxcare.1 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6589a902-3400-5a5a-85be-a315d4dcc332",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 7.2.0-tuxcare.1 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:29ebc05d-ac50-58d9-89c7-2a02b8e4a426",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 7.2.0-tuxcare.1 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3976c3e8-8881-51d9-a24a-09262d95d603",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 7.2.0-tuxcare.1 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a2a2d1e0-cc74-5632-8647-eb1789a11713",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 7.2.0-tuxcare.1 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:534bf3db-2584-576c-b25e-a71982500309",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 7.2.0-tuxcare.1 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a8681800-41e3-57ba-842b-07fe424c550d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 7.2.0-tuxcare.1 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9e4a83e5-7f93-5532-b446-70a09c5fa8ee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 7.2.0-tuxcare.1 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1629642d-a274-551f-8901-ad4c284c28a1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 7.2.0-tuxcare.1 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:69222b0e-3349-576b-9305-9d4f65a0f0e7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 7.2.0-tuxcare.1 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cc9d9b0b-1abd-517e-add2-186d6ec54196",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 7.2.0-tuxcare.1 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9bda5d6c-257c-5be6-845f-7c25d567f563",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 7.2.0-tuxcare.1 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9c9a4a38-5175-5def-8c4c-aa538fd95705",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 7.2.0-tuxcare.1 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c9f6cded-5a49-523d-92c7-2539b28a3fa8",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 7.2.0-tuxcare.1 of @angular/router. not_affected \u2014 Angular v7.2.0 is NOT AFFECTED by CVE-2026-68945. The vulnerable component (HttpTransferCache) does not exist in this version. According to patch documentation in the repository (CVE-2026-50170.patch, CVE-2026-54266.patch), the HTTP transfer-cache and client hydration features were introduced in Angular v16. Angular v7.2.0 predates this feature by many major versions. Exhaustive searches confir...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:19e17851-ada2-5572-8793-8c131a3946c1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 7.2.0-tuxcare.1 of @angular/router, and is fixed in 7.2.0-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b883a277-8261-570a-8931-b64bc0f56636",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 7.2.0-tuxcare.1 of @angular/router, and is fixed in 7.2.0-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a9a5df6b-9302-5331-825c-7e05ed432de2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 7.2.0-tuxcare.1 of @angular/router. not_affected \u2014 Angular version 7.2.0 is not affected by CVE-2026-88056. The vulnerability requires the presence of a `parseUrl` function in `packages/platform-server/src/url.ts` that uses `String.prototype.trim()` to normalize URLs, which strips Unicode whitespace and can convert validated same-origin relative URLs into cross-origin protocol-relative URLs. Version 7.2.0 does not contain the `url.ts` file; it ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:83fde707-0a39-531a-93b8-fe2896724ada",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 7.2.0-tuxcare.1 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2f3ca91e-0d19-50c9-8fe3-395fbb6aabd7",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 7.2.0-tuxcare.1 of @angular/router. not_affected \u2014 Angular v7.2.0 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache, hierarchical HttpClient delegation (withRequestsMadeViaParent()), and automatic HTTP response caching features that were introduced in Angular v16+. Version 7.2.0 uses NgModule-based configuration (HttpClientModule) with manual TransferState only\u2014no automatic HTTP-to-TransferState caching exists. The...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5859fd94-54a8-5358-90b8-e49d68cbcea7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 7.2.0-tuxcare.1 of @angular/router."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.1"
    }
  ]
}