{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f3c6aaf7-8c80-5aa3-864e-f16274b709e1",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/upgrade",
      "purl": "pkg:npm/%40angular/upgrade@7.2.16-tuxcare.2",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/upgrade@7.2.16-tuxcare.2",
      "version": "7.2.16-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4fe3af4e-0075-5481-a083-2a62146c13ed",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-4231 affects version 7.2.16-tuxcare.2 of @angular/upgrade, and is fixed in 7.2.16-tuxcare.4."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9bd2ab5d-9335-5d1b-9250-5d7cd9a68e55",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 7.2.16-tuxcare.2 of @angular/upgrade, and is fixed in 7.2.16-tuxcare.10."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:520f0926-1fad-5950-841f-5f29291c1fb2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 7.2.16-tuxcare.2 of @angular/upgrade, and is fixed in 7.2.16-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2326495d-c4d8-5608-b6b4-a995d22d77a0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 7.2.16-tuxcare.2 of @angular/upgrade, and is fixed in 7.2.16-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4135ef02-c405-5c16-945f-52de48f1a3f4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 7.2.16-tuxcare.2 of @angular/upgrade, and is fixed in 7.2.16-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c9ed2885-5d67-5a9a-8188-044ec0e8df2f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 7.2.16-tuxcare.2 of @angular/upgrade, and is fixed in 7.2.16-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:dbc2f8e6-1ba8-500c-ad3a-47a8c4dba2d2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 7.2.16-tuxcare.2 of @angular/upgrade, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c35a184d-9365-5370-9736-6f513365bc3d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 7.2.16-tuxcare.2 of @angular/upgrade, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:34a0f4d9-9a85-55cb-ae6a-7ab97f6039ec",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 7.2.16-tuxcare.2 of @angular/upgrade, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5260bae7-5889-5d6d-beba-697641fd6b95",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 7.2.16-tuxcare.2 of @angular/upgrade, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a83210a9-416b-514d-a97e-9de3173e1a38",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 7.2.16-tuxcare.2 of @angular/upgrade, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:bc34d785-d8a0-5bc5-8207-b0c58e5f18c5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 7.2.16-tuxcare.2 of @angular/upgrade, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8b1d46a9-85d9-5c8d-989c-78e89e1ab48f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 7.2.16-tuxcare.2 of @angular/upgrade, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ac1b0a3d-672b-548a-ad5b-511a88d3c454",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 7.2.16-tuxcare.2 of @angular/upgrade, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:63457398-d759-5045-aeba-0261679707b9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 7.2.16-tuxcare.2 of @angular/upgrade, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:92beb137-68a4-5864-82b4-829057c90057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 7.2.16-tuxcare.2 of @angular/upgrade, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6ecd34e0-f89d-5b9f-864e-ceb18367603e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 7.2.16-tuxcare.2 of @angular/upgrade, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fa51dd79-22c6-56a5-8812-9515c1360f02",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 7.2.16-tuxcare.2 of @angular/upgrade, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1f6a0e36-3580-5234-8a62-358830fc40a5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 7.2.16-tuxcare.2 of @angular/upgrade, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e3f29af8-50bc-58ea-a04e-02dd8da61adb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 7.2.16-tuxcare.2 of @angular/upgrade, and is fixed in 7.2.16-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a0978bc4-1224-5630-94ed-d7cbb6ec0ad9",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 7.2.16-tuxcare.2 of @angular/upgrade. not_affected \u2014 Angular 7.2.16 is not affected by CVE-2026-68945. The vulnerability concerns HttpTransferCache's cache key generation logic that treats repeated HTTP parameters (`?role=user&role=admin`) and comma-separated values (`?role=user,admin`) as identical, causing cache key collisions. However, the HttpTransferCache feature does not exist in version 7.2.16\u2014it was introduced in Angular v16. While v7.2.1...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:372d0fc6-17e4-5b6e-a89d-288558149ee1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 7.2.16-tuxcare.2 of @angular/upgrade, and is fixed in 7.2.16-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:20a90899-ace7-5de8-8d3f-42cfa9ea0a1c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 7.2.16-tuxcare.2 of @angular/upgrade, and is fixed in 7.2.16-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d75882a0-8938-5ead-8013-1c3d3783b96f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 7.2.16-tuxcare.2 of @angular/upgrade. not_affected \u2014 Angular 7.2.16 is not affected by CVE-2026-88056. The vulnerability requires a String.prototype.trim() call on URLs during server-side rendering that strips Unicode whitespace characters, converting same-origin relative URLs into cross-origin protocol-relative URLs. This vulnerable code pattern does not exist in Angular 7.2.16. The CVE describes a vulnerability introduced in later Angular versi...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:50f024e4-6460-5190-b720-1747e8ce9627",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88057 does not affect version 7.2.16-tuxcare.2 of @angular/upgrade. not_affected \u2014 Angular 7.2.16 is not affected by CVE-2026-88057. The vulnerability exists in the Ivy compiler's template pipeline (introduced in Angular 9+), which does not exist in this version. Angular 7.2.16 uses View Engine, where the SecurityContext determination for directive host bindings correctly uses the concrete host element name (`element.name`) rather than the directive's selector. The exploitati...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:cdc22f95-cf52-5e09-a549-afb959f18dff",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 7.2.16-tuxcare.2 of @angular/upgrade. not_affected \u2014 Angular 7.2.16 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, withRequestsMadeViaParent(), and client hydration features that were introduced in Angular v16+. Angular 7.2.16 predates these features by approximately 7 major versions. The codebase contains only legacy TransferState (manual key-value store) and NgModule-based HttpClient (no hierarchical delegation...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@7.2.16-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:75df1c14-1f97-5e57-8c20-9763b62df8a6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 7.2.16-tuxcare.2 of @angular/upgrade."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/upgrade@7.2.16-tuxcare.2"
    }
  ]
}