{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2481ab3a-a058-50e0-b80b-e2c9cea1b993",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/router",
      "purl": "pkg:npm/%40angular/router@7.2.16-tuxcare.5",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/router@7.2.16-tuxcare.5",
      "version": "7.2.16-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.16-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5661c47f-35dd-5901-bcd3-91ca4a6e047d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 7.2.16-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.16-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f0565378-0769-549a-bfdd-f08c0b794461",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 7.2.16-tuxcare.5 of @angular/router, and is fixed in 7.2.16-tuxcare.10."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.16-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ada7a1a5-9c5f-5f6e-b01f-39ccfd686fb6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 7.2.16-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.16-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:015c6352-e882-55be-8c65-a33a7bde6537",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 7.2.16-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.16-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:aee2b67e-a5c4-558d-bc36-bfd344af4a56",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 7.2.16-tuxcare.5 of @angular/router, and is fixed in 7.2.16-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.16-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4214d5ee-c18c-51fd-b7ce-c17c8dd02b78",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 7.2.16-tuxcare.5 of @angular/router, and is fixed in 7.2.16-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.16-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1e8e122d-e89b-5864-8eb2-21bdbeffe2c9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 7.2.16-tuxcare.5 of @angular/router, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.16-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f3007cfe-c696-5229-a336-c26ae0fe13ed",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 7.2.16-tuxcare.5 of @angular/router, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.16-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:fc12c102-8c72-53bb-a7fa-c91b8e805d8b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 7.2.16-tuxcare.5 of @angular/router, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.16-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6e8dd132-c807-5021-989a-ffb35d08195e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 7.2.16-tuxcare.5 of @angular/router, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.16-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:87dfe1df-36a2-5fb1-b662-9d456cfa5dbf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 7.2.16-tuxcare.5 of @angular/router, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.16-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:885c583c-38d8-5c6b-bcc8-acb9a2fdbdf6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 7.2.16-tuxcare.5 of @angular/router, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.16-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7211bf21-1731-59c9-84ea-08acae34ca9a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 7.2.16-tuxcare.5 of @angular/router, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.16-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9bfd7e15-7250-52c1-adc0-adc75e75ea7b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 7.2.16-tuxcare.5 of @angular/router, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.16-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:839cde1d-4333-506e-9901-60e00fbdfe58",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 7.2.16-tuxcare.5 of @angular/router, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.16-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:bdba6db6-52c3-5799-a538-200440f90ea7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 7.2.16-tuxcare.5 of @angular/router, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.16-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:01871d05-9309-5c31-adc3-43a5558df885",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 7.2.16-tuxcare.5 of @angular/router, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.16-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:16006ccb-3c5b-56f9-8e9a-e3ecd7bea442",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 7.2.16-tuxcare.5 of @angular/router, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.16-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0f62d57c-f1d2-5c6c-8eb8-ac82a6c4633d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 7.2.16-tuxcare.5 of @angular/router, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.16-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1848fc4c-3041-5a0d-a576-13663b924dc6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 7.2.16-tuxcare.5 of @angular/router, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.16-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:be7a7348-3d2b-5ebd-b8a8-fe2505be3a82",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 7.2.16-tuxcare.5 of @angular/router. not_affected \u2014 Angular 7.2.16 is not affected by CVE-2026-68945. The vulnerability concerns HttpTransferCache's cache key generation logic that treats repeated HTTP parameters (`?role=user&role=admin`) and comma-separated values (`?role=user,admin`) as identical, causing cache key collisions. However, the HttpTransferCache feature does not exist in version 7.2.16\u2014it was introduced in Angular v16. While v7.2.1...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.16-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:68f28094-85bf-5493-ad6a-8fbbd565621a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 7.2.16-tuxcare.5 of @angular/router, and is fixed in 7.2.16-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.16-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6ecf6019-bf61-5ef9-9637-347d974a7649",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 7.2.16-tuxcare.5 of @angular/router, and is fixed in 7.2.16-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.16-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:040cbf79-363c-5edc-83f3-81fd70492c77",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 7.2.16-tuxcare.5 of @angular/router. not_affected \u2014 Angular 7.2.16 is not affected by CVE-2026-88056. The vulnerability requires a String.prototype.trim() call on URLs during server-side rendering that strips Unicode whitespace characters, converting same-origin relative URLs into cross-origin protocol-relative URLs. This vulnerable code pattern does not exist in Angular 7.2.16. The CVE describes a vulnerability introduced in later Angular versi...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.16-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:95612117-e745-531d-ad5b-96fdbb21f9ab",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88057 does not affect version 7.2.16-tuxcare.5 of @angular/router. not_affected \u2014 Angular 7.2.16 is not affected by CVE-2026-88057. The vulnerability exists in the Ivy compiler's template pipeline (introduced in Angular 9+), which does not exist in this version. Angular 7.2.16 uses View Engine, where the SecurityContext determination for directive host bindings correctly uses the concrete host element name (`element.name`) rather than the directive's selector. The exploitati...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.16-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7a862e1c-0f11-546e-b4e6-771d907b1394",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 7.2.16-tuxcare.5 of @angular/router. not_affected \u2014 Angular 7.2.16 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, withRequestsMadeViaParent(), and client hydration features that were introduced in Angular v16+. Angular 7.2.16 predates these features by approximately 7 major versions. The codebase contains only legacy TransferState (manual key-value store) and NgModule-based HttpClient (no hierarchical delegation...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.16-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:178693d3-45f6-5307-890c-214465e121d1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 7.2.16-tuxcare.5 of @angular/router."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/router@7.2.16-tuxcare.5"
    }
  ]
}