{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:63939ea9-e293-5292-a0d7-ebcb66ba07c6",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/forms@7.2.16-tuxcare.2",
      "type": "library",
      "name": "@angular/forms",
      "version": "7.2.16-tuxcare.2",
      "purl": "pkg:npm/%40angular/forms@7.2.16-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:dfd6393d-9eac-5186-921f-b6e2428ae41e",
      "id": "CVE-2021-4231",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-4231 affects version 7.2.16-tuxcare.2 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@7.2.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88b9401d-3b1d-5ecf-a05f-59e6dc936f97",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 7.2.16-tuxcare.2 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@7.2.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a18ef672-1a60-517b-9d90-86fd6551a936",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 7.2.16-tuxcare.2 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@7.2.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b21ffa5b-2272-57c6-8f92-4c75a940b9aa",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 7.2.16-tuxcare.2 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@7.2.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85e535b0-f7e0-5dbf-864f-468d1700172e",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 7.2.16-tuxcare.2 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@7.2.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4517d0b3-03d7-5f46-8a5c-d58974047fba",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 7.2.16-tuxcare.2 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@7.2.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b06a3323-e7f3-5ad5-9703-409c09f06296",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 7.2.16-tuxcare.2 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@7.2.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e792c9fd-3dd9-533d-b99e-e17ef8151f9c",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 7.2.16-tuxcare.2 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@7.2.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:379d4ff5-58fc-5fd5-85bc-cda57ff30ae7",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 7.2.16-tuxcare.2 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@7.2.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44106f5e-5d07-5130-8854-ad11a991e2d1",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 7.2.16-tuxcare.2 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@7.2.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdc5594f-bbda-5855-bbf7-17cfaac7e6b0",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 7.2.16-tuxcare.2 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@7.2.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82a20df4-2d13-5a0f-ab4f-9a2674b0fd7c",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 7.2.16-tuxcare.2 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@7.2.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94fd2e13-5e53-53e6-8b87-5690c26b64b1",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 7.2.16-tuxcare.2 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@7.2.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d69944a5-f2bd-58c8-a722-dd3d55a4303c",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 7.2.16-tuxcare.2 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@7.2.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7eb925db-f47f-5d3b-ad3f-9eeb7c0301f3",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 7.2.16-tuxcare.2 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@7.2.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da495795-dcbd-5ff9-8bd2-d91d21f9fd6a",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 7.2.16-tuxcare.2 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@7.2.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c58a5b0a-f453-5306-9c7a-9789e9955a93",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 7.2.16-tuxcare.2 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@7.2.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01e05203-aaa8-54ee-a1ce-51e402c540cb",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 7.2.16-tuxcare.2 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@7.2.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f83a93c-4f42-5f26-b740-0fcca55d83f3",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 7.2.16-tuxcare.2 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@7.2.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34768c22-bd9b-54b9-95f1-9023150fe9b0",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 7.2.16-tuxcare.2 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@7.2.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf08e389-0d39-540f-8ef1-ac3467ac9f6c",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 7.2.16-tuxcare.2 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@7.2.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:187ddfe0-5006-504a-8077-f3535a5eb6f9",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 7.2.16-tuxcare.2 of @angular/forms. not_affected \u2014 Angular 7.2.16 is not affected by CVE-2026-68945. The vulnerability concerns HttpTransferCache's cache key generation logic that treats repeated HTTP parameters (`?role=user&role=admin`) and comma-separated values (`?role=user,admin`) as identical, causing cache key collisions. However, the HttpTransferCache feature does not exist in version 7.2.16\u2014it was introduced in Angular v16. While v7.2.1..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@7.2.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:672d568f-9617-5655-ada0-5267e003ebfa",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 7.2.16-tuxcare.2 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@7.2.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62d8c7b7-4cee-54b9-a4f2-7e24d556ad7c",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 7.2.16-tuxcare.2 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@7.2.16-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/forms@7.2.16-tuxcare.2"
    }
  ]
}