{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:67d24ec3-c252-5f2d-a476-7c2db9818ee2",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/compiler",
      "purl": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4",
      "version": "7.2.0-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:df518222-740c-5f86-aac8-559e4390e58e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 7.2.0-tuxcare.4 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e851a1a5-af80-5b09-bc04-03dd3431cc0f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 7.2.0-tuxcare.4 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6d3f9b71-beba-58b8-9521-8f22ef45a747",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 7.2.0-tuxcare.4 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8b4736e8-29e9-5102-9070-2eba7a74511a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-101895 does not affect version 7.2.0-tuxcare.4 of @angular/compiler. not_affected \u2014 CVE-2026-101895 affects domino's HTML parser (lib/HTMLParser.js), which is declared as a dependency in Angular's package.json (domino@2.1.0) but is NOT vendored or present in this repository's source tree. While Angular SSR applications using this version ARE exploitable (user input via [innerHTML] bindings reaches domino's vulnerable parser without DOCTYPE validation), the TARGET REPOSITORY do...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f14c71ae-eaec-5df0-8ded-fc00f7e2e005",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 7.2.0-tuxcare.4 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e4036f43-21e2-505f-9318-2169a9a1b00a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 7.2.0-tuxcare.4 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:782743d7-cc6d-5084-b248-18d376853508",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 7.2.0-tuxcare.4 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:840f98e2-3be3-5d35-b0fc-786f37be6ecc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 7.2.0-tuxcare.4 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:efb6933a-5722-5f3a-9e45-f0a5af403f6b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 7.2.0-tuxcare.4 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5eff2d16-4e15-5b2b-ab99-efa23ebeb0f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 7.2.0-tuxcare.4 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5e475c24-6bc7-5257-b55e-4a9de0fe747d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 7.2.0-tuxcare.4 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:25c9aa84-ce3b-50f9-9208-2a54e5d51422",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 7.2.0-tuxcare.4 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0ce869ba-3dd1-5944-8741-ec566973e740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 7.2.0-tuxcare.4 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:2d79e1cc-b87b-51d1-86a1-46a1ee6ed0e0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 7.2.0-tuxcare.4 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0abf2297-24f6-510e-b977-3673f3521eee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 7.2.0-tuxcare.4 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:2d173347-afbb-5b8f-9e78-f85424ca18b7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 7.2.0-tuxcare.4 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:69a0214e-b0dd-56a6-9935-9f4a7e4ddb56",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 7.2.0-tuxcare.4 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a0d0be3c-0c8e-5081-b257-db63bd0d6d62",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 7.2.0-tuxcare.4 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:bad46a85-5650-5113-b101-f5594245a160",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 7.2.0-tuxcare.4 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:36636b90-cd1a-5060-9016-9bd80c26c3dd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 7.2.0-tuxcare.4 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a24e7349-a61d-5a67-88b2-76cb013558ef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 7.2.0-tuxcare.4 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:fbe70e54-6d9a-542d-b474-483b78f4fc12",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 7.2.0-tuxcare.4 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:581e881c-3df5-5ce6-99b9-279f69388397",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 7.2.0-tuxcare.4 of @angular/compiler. not_affected \u2014 Angular v7.2.0 is NOT AFFECTED by CVE-2026-68945. The vulnerable component (HttpTransferCache) does not exist in this version. According to patch documentation in the repository (CVE-2026-50170.patch, CVE-2026-54266.patch), the HTTP transfer-cache and client hydration features were introduced in Angular v16. Angular v7.2.0 predates this feature by many major versions. Exhaustive searches confir...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:89a04aad-6847-52dc-96b4-9cca9f101332",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 7.2.0-tuxcare.4 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d6031de5-9590-562f-8e1b-95d9169aa30c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 7.2.0-tuxcare.4 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d1d1f6bb-b547-5261-bdb7-c6197c4d44d5",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 7.2.0-tuxcare.4 of @angular/compiler. not_affected \u2014 Angular version 7.2.0 is not affected by CVE-2026-88056. The vulnerability requires the presence of a `parseUrl` function in `packages/platform-server/src/url.ts` that uses `String.prototype.trim()` to normalize URLs, which strips Unicode whitespace and can convert validated same-origin relative URLs into cross-origin protocol-relative URLs. Version 7.2.0 does not contain the `url.ts` file; it ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3a9aa0f1-bc52-52d5-a42c-8107c5cb20d4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 7.2.0-tuxcare.4 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:dbf36d14-f59d-5757-a7eb-7ebb074cece4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 7.2.0-tuxcare.4 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1fddb41f-c1c0-569e-b8b0-2077fe91d57c",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 7.2.0-tuxcare.4 of @angular/compiler. not_affected \u2014 Angular v7.2.0 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache, hierarchical HttpClient delegation (withRequestsMadeViaParent()), and automatic HTTP response caching features that were introduced in Angular v16+. Version 7.2.0 uses NgModule-based configuration (HttpClientModule) with manual TransferState only\u2014no automatic HTTP-to-TransferState caching exists. The...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:82993a66-f660-502d-bb78-04d368bec53a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 7.2.0-tuxcare.4 of @angular/compiler."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler@7.2.0-tuxcare.4"
    }
  ]
}