{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:cc65a146-cd44-56d3-8f76-c64fc8bd9bdf",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/elements",
      "purl": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4",
      "version": "7.2.0-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:22ea1669-1f0b-5298-ba99-b6462f87639c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 7.2.0-tuxcare.4 of @angular/elements."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5f5a1910-880a-5ba0-9353-30e57ad732cd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 7.2.0-tuxcare.4 of @angular/elements."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ef03f71a-5470-5a9b-8cb9-9b2870232b4b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 7.2.0-tuxcare.4 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9ed6a3a5-14a4-52b2-a362-17b529cd4f92",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-101895 does not affect version 7.2.0-tuxcare.4 of @angular/elements. not_affected \u2014 CVE-2026-101895 affects domino's HTML parser (lib/HTMLParser.js), which is declared as a dependency in Angular's package.json (domino@2.1.0) but is NOT vendored or present in this repository's source tree. While Angular SSR applications using this version ARE exploitable (user input via [innerHTML] bindings reaches domino's vulnerable parser without DOCTYPE validation), the TARGET REPOSITORY do...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3972e833-e349-5c08-8e1d-b5d95d9b9090",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 7.2.0-tuxcare.4 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:80df07e7-3c0e-54f4-a5e9-bca8853bb0d8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 7.2.0-tuxcare.4 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1b8ecf66-6a98-5e82-8900-9049b9e16aef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 7.2.0-tuxcare.4 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:49bc5902-b1ad-5bb1-aae3-cdabb32a370b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 7.2.0-tuxcare.4 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e02b6c86-fe15-5701-aa38-d9cf63cb416f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 7.2.0-tuxcare.4 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8517bed9-dddc-5c6b-a13f-027f2b99faf5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 7.2.0-tuxcare.4 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:be8ed024-9ddf-5f3b-bc2d-fc4d05fab45e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 7.2.0-tuxcare.4 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:38201aaa-7eb2-52a7-ba5d-ddf37de08df9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 7.2.0-tuxcare.4 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6787868e-2f2e-5831-99e7-bf2cc1064885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 7.2.0-tuxcare.4 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:41a42fc1-1457-5dc5-bb6a-e611bbe03c15",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 7.2.0-tuxcare.4 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f62f6aac-54ef-53ee-9085-36553452ce2a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 7.2.0-tuxcare.4 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f628b500-14e3-5717-8865-03bc6ab521c7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 7.2.0-tuxcare.4 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c75ab01f-0d4a-519f-842e-2b1c952e046d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 7.2.0-tuxcare.4 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:81e3f397-4cfa-5f31-80a4-16a4fe6cbc5b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 7.2.0-tuxcare.4 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b0e850ec-bbf3-5db5-91a4-5e60205c22aa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 7.2.0-tuxcare.4 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f7585cf0-a7d0-574f-b3b4-f5f49dcf5e62",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 7.2.0-tuxcare.4 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:dfba53a7-f329-534f-9481-2cac940ba607",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 7.2.0-tuxcare.4 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:30fda67f-ce5d-55c8-b721-000661076bf4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 7.2.0-tuxcare.4 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:40806533-cef2-523f-85a5-2f0c36e48cd6",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 7.2.0-tuxcare.4 of @angular/elements. not_affected \u2014 Angular v7.2.0 is NOT AFFECTED by CVE-2026-68945. The vulnerable component (HttpTransferCache) does not exist in this version. According to patch documentation in the repository (CVE-2026-50170.patch, CVE-2026-54266.patch), the HTTP transfer-cache and client hydration features were introduced in Angular v16. Angular v7.2.0 predates this feature by many major versions. Exhaustive searches confir...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:82fd6e90-a77b-5935-98d7-99a6cc233a93",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 7.2.0-tuxcare.4 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6626c19c-cd51-55c6-8051-dfc42c6c6180",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 7.2.0-tuxcare.4 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:75c8b3e5-f4be-5740-adf3-cc26f06d254d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 7.2.0-tuxcare.4 of @angular/elements. not_affected \u2014 Angular version 7.2.0 is not affected by CVE-2026-88056. The vulnerability requires the presence of a `parseUrl` function in `packages/platform-server/src/url.ts` that uses `String.prototype.trim()` to normalize URLs, which strips Unicode whitespace and can convert validated same-origin relative URLs into cross-origin protocol-relative URLs. Version 7.2.0 does not contain the `url.ts` file; it ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a1c8d8d0-cabf-5fc6-ab5e-2b180c3e7be7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 7.2.0-tuxcare.4 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:523f73f8-dff1-5be5-b80a-89094d2f9aea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 7.2.0-tuxcare.4 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7dfa0f50-e65d-51f3-b183-30013a630192",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 7.2.0-tuxcare.4 of @angular/elements. not_affected \u2014 Angular v7.2.0 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache, hierarchical HttpClient delegation (withRequestsMadeViaParent()), and automatic HTTP response caching features that were introduced in Angular v16+. Version 7.2.0 uses NgModule-based configuration (HttpClientModule) with manual TransferState only\u2014no automatic HTTP-to-TransferState caching exists. The...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:2d706c05-0d0d-576c-8372-59f050e7b23e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 7.2.0-tuxcare.4 of @angular/elements."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.4"
    }
  ]
}