{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:72106c8d-b4e4-5d9a-8c29-a37d18da726d",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/service-worker",
      "purl": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3",
      "version": "7.2.0-tuxcare.3",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:def7d23a-9c91-50fb-8e4c-577f06cf40b9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 7.2.0-tuxcare.3 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:0dc152a6-6bd0-5dbc-84f3-078528053e94",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 7.2.0-tuxcare.3 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:be71d57b-f0c2-5a12-a7a4-0b562b88a8dd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 7.2.0-tuxcare.3 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:3ccfef3a-3be1-50fb-b04e-fb30b5472716",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 7.2.0-tuxcare.3 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:2e7e6a9c-d74e-50d5-aee9-d8cf503099cb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 7.2.0-tuxcare.3 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:74e85e97-10b5-5b47-9b18-da47957d269e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 7.2.0-tuxcare.3 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:94c6e8c9-b93d-5368-82c3-819f0c4051dc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 7.2.0-tuxcare.3 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:c6bd63b4-0c33-5e27-a38c-b721dd61d6ca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 7.2.0-tuxcare.3 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:3c786764-40fe-5bdc-98e2-cb8eed72d46f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 7.2.0-tuxcare.3 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:349bc00a-9641-519b-83a8-14a288705e0e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 7.2.0-tuxcare.3 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:ee28d100-68a3-56d5-92b1-a6547415471f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 7.2.0-tuxcare.3 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:cd260c91-46b2-5d16-9ec4-7ba2634835c1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 7.2.0-tuxcare.3 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:79ef9bc7-e392-52dd-b8b5-dd32ff6ce89d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 7.2.0-tuxcare.3 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:885774a4-ee16-509d-b887-d4c143c6c632",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 7.2.0-tuxcare.3 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:633a9001-fc3d-51a9-b3e1-4676c91487bb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 7.2.0-tuxcare.3 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:20f2a6de-ae09-56ce-9c83-65a7b17e7664",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 7.2.0-tuxcare.3 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:19303031-aa77-5aef-99c3-b9a4b942a6c5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 7.2.0-tuxcare.3 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:5abca6e6-41e6-5bb7-add6-aa5f399117da",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 7.2.0-tuxcare.3 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:7396bc61-739c-5d90-b557-c5e4c498b6f5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 7.2.0-tuxcare.3 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:959184d9-fd8a-5c2f-83d7-e8ad46ee82e5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 7.2.0-tuxcare.3 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:8b832a27-8305-5dfb-a479-4b824ced591b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 7.2.0-tuxcare.3 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:da9a1ead-50d2-556c-86f3-9d2d995bcf14",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 7.2.0-tuxcare.3 of @angular/service-worker. not_affected \u2014 Angular v7.2.0 is NOT AFFECTED by CVE-2026-68945. The vulnerable component (HttpTransferCache) does not exist in this version. According to patch documentation in the repository (CVE-2026-50170.patch, CVE-2026-54266.patch), the HTTP transfer-cache and client hydration features were introduced in Angular v16. Angular v7.2.0 predates this feature by many major versions. Exhaustive searches confir...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:eebf89e1-49d9-5e49-96ff-ee1b4e70daa7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 7.2.0-tuxcare.3 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:b88879f3-abdc-54b8-911a-ca0bb506da5e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 7.2.0-tuxcare.3 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:d3abd7ee-e142-58a1-b602-4349cbdb3c66",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 7.2.0-tuxcare.3 of @angular/service-worker. not_affected \u2014 Angular version 7.2.0 is not affected by CVE-2026-88056. The vulnerability requires the presence of a `parseUrl` function in `packages/platform-server/src/url.ts` that uses `String.prototype.trim()` to normalize URLs, which strips Unicode whitespace and can convert validated same-origin relative URLs into cross-origin protocol-relative URLs. Version 7.2.0 does not contain the `url.ts` file; it ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:91cbc933-01e7-5de1-8ca4-f56d570f8565",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 7.2.0-tuxcare.3 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:cf719211-07ba-50f0-97ca-129a03289269",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 7.2.0-tuxcare.3 of @angular/service-worker. not_affected \u2014 Angular v7.2.0 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache, hierarchical HttpClient delegation (withRequestsMadeViaParent()), and automatic HTTP response caching features that were introduced in Angular v16+. Version 7.2.0 uses NgModule-based configuration (HttpClientModule) with manual TransferState only\u2014no automatic HTTP-to-TransferState caching exists. The...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:9a1f8609-668c-56b3-86d3-b5bd7aef9ea4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 7.2.0-tuxcare.3 of @angular/service-worker."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.3"
    }
  ]
}