{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7ee1b3c2-83c8-5aaa-99bf-d32d05392c16",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/benchpress",
      "purl": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4",
      "version": "7.2.0-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e295a8c4-2538-5746-ab5a-77bdfe132256",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 7.2.0-tuxcare.4 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:af74ea4c-55b2-51b5-8695-1927f92993d1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 7.2.0-tuxcare.4 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:43ba59e6-bff9-512d-ae37-066757242f20",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 7.2.0-tuxcare.4 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:2f6422fe-f2c8-5c93-b327-55b9eb3e7a05",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-101895 does not affect version 7.2.0-tuxcare.4 of @angular/benchpress. not_affected \u2014 CVE-2026-101895 affects domino's HTML parser (lib/HTMLParser.js), which is declared as a dependency in Angular's package.json (domino@2.1.0) but is NOT vendored or present in this repository's source tree. While Angular SSR applications using this version ARE exploitable (user input via [innerHTML] bindings reaches domino's vulnerable parser without DOCTYPE validation), the TARGET REPOSITORY do...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:aff0484d-3cad-53bc-9101-3eb3d0566db0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 7.2.0-tuxcare.4 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c74ced96-2fdc-5b89-aff4-dd2858aedbf5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 7.2.0-tuxcare.4 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:dd922c55-3572-580b-9cbc-aa68b77282da",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 7.2.0-tuxcare.4 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f55f6977-7c61-5498-a57b-bc08e0693b52",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 7.2.0-tuxcare.4 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d96690a5-a693-5910-a583-5f2487b1436d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 7.2.0-tuxcare.4 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:93b9b50c-eae2-50bd-945d-b834b37dd0a9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 7.2.0-tuxcare.4 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:dcf5bed8-ab90-58d9-9391-6d49bd34e41e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 7.2.0-tuxcare.4 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:fb0d27c2-03e0-5735-ae4c-2ec514b48b5a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 7.2.0-tuxcare.4 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:538dc27d-d676-54ca-b92d-906185841842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 7.2.0-tuxcare.4 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:705f713e-3ab4-5985-8895-cfafb15c69ec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 7.2.0-tuxcare.4 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:745d8a94-31b0-5549-9e55-0b1025a53bed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 7.2.0-tuxcare.4 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9325a6df-0a05-5098-883b-24fc9671c38d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 7.2.0-tuxcare.4 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0e751237-278d-59a2-b6c2-ba505882cc24",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 7.2.0-tuxcare.4 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:31a11680-eaa6-5dfa-8c6c-6bb2e22b4510",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 7.2.0-tuxcare.4 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:004c6aa5-032f-5c2c-bd03-d3ee0ad5870f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 7.2.0-tuxcare.4 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:70fbace2-55e8-59e0-ad5d-e52988791fb6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 7.2.0-tuxcare.4 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5a0bac20-c9d4-56f3-af6d-b562947b571c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 7.2.0-tuxcare.4 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a8e10cd0-2b02-5e9f-93a6-1dff8f8d752b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 7.2.0-tuxcare.4 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:29be8f90-2f0b-5075-bcf9-adab81b9bc57",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 7.2.0-tuxcare.4 of @angular/benchpress. not_affected \u2014 Angular v7.2.0 is NOT AFFECTED by CVE-2026-68945. The vulnerable component (HttpTransferCache) does not exist in this version. According to patch documentation in the repository (CVE-2026-50170.patch, CVE-2026-54266.patch), the HTTP transfer-cache and client hydration features were introduced in Angular v16. Angular v7.2.0 predates this feature by many major versions. Exhaustive searches confir...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:470c424a-1756-5b52-89f8-903ef2caeb05",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 7.2.0-tuxcare.4 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:467857f3-8755-588c-aede-25003176d1de",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 7.2.0-tuxcare.4 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:be908ece-6f8c-5687-973a-17b7b5c2e7ca",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 7.2.0-tuxcare.4 of @angular/benchpress. not_affected \u2014 Angular version 7.2.0 is not affected by CVE-2026-88056. The vulnerability requires the presence of a `parseUrl` function in `packages/platform-server/src/url.ts` that uses `String.prototype.trim()` to normalize URLs, which strips Unicode whitespace and can convert validated same-origin relative URLs into cross-origin protocol-relative URLs. Version 7.2.0 does not contain the `url.ts` file; it ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:fff1794d-c894-5cdf-bc90-8859099a962b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 7.2.0-tuxcare.4 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b7f5ea88-3314-5af2-8c4c-720ada4a7603",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 7.2.0-tuxcare.4 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5f52ff72-267f-5cca-b4b6-3bb680817927",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 7.2.0-tuxcare.4 of @angular/benchpress. not_affected \u2014 Angular v7.2.0 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache, hierarchical HttpClient delegation (withRequestsMadeViaParent()), and automatic HTTP response caching features that were introduced in Angular v16+. Version 7.2.0 uses NgModule-based configuration (HttpClientModule) with manual TransferState only\u2014no automatic HTTP-to-TransferState caching exists. The...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:30288486-c76f-5823-a7bf-48b78aa1ae04",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 7.2.0-tuxcare.4 of @angular/benchpress."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/benchpress@7.2.0-tuxcare.4"
    }
  ]
}