{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:73af9121-6b82-534e-8248-b37aefe0e1f5",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/platform-webworker",
      "purl": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4",
      "version": "7.2.0-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:217f4771-a1f6-53ee-ab3b-80a90bdbfcc0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 7.2.0-tuxcare.4 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:082c88b6-91a6-50c8-9384-4a5390c51271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 7.2.0-tuxcare.4 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3c890f18-0c76-50c5-9dee-9e06c1a6ca62",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 7.2.0-tuxcare.4 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0f7bb7bc-5ba4-588a-9a2d-fd497067391d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-101895 does not affect version 7.2.0-tuxcare.4 of @angular/platform-webworker. not_affected \u2014 CVE-2026-101895 affects domino's HTML parser (lib/HTMLParser.js), which is declared as a dependency in Angular's package.json (domino@2.1.0) but is NOT vendored or present in this repository's source tree. While Angular SSR applications using this version ARE exploitable (user input via [innerHTML] bindings reaches domino's vulnerable parser without DOCTYPE validation), the TARGET REPOSITORY do...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a87911e2-6f8c-528f-9081-1818c23381e4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 7.2.0-tuxcare.4 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:fbee3d34-a948-5bfe-ae9e-ea38ded448fb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 7.2.0-tuxcare.4 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6c15e610-e7c5-5cef-a826-c44f0c6814f5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 7.2.0-tuxcare.4 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d9f2e5a1-e72c-523d-a0b5-70d7c8f84a22",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 7.2.0-tuxcare.4 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0ec6d7f3-042c-5b97-862a-bd5c241563cc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 7.2.0-tuxcare.4 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3f9738d8-dc38-5aae-930e-70f3598fb38a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 7.2.0-tuxcare.4 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:dc26400c-b2a0-56ae-a1a3-d9e73c999fda",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 7.2.0-tuxcare.4 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:587ee66f-6e13-5a8e-a4a3-17b8263994a4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 7.2.0-tuxcare.4 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:2ebe114f-76de-5084-ae68-f44a88ea3db8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 7.2.0-tuxcare.4 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a98c613e-3c14-5013-bb72-75924aba6b16",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 7.2.0-tuxcare.4 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:4d898ca7-5e82-54c9-a2c9-65691a711315",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 7.2.0-tuxcare.4 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d7c3dc58-2ef6-5617-98d4-aa0ab9b4bcc4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 7.2.0-tuxcare.4 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b0da562b-67fe-56d2-8040-3c08672aae94",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 7.2.0-tuxcare.4 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:2c716ca1-a7ef-598e-a111-fe691872e055",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 7.2.0-tuxcare.4 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e3c08978-9d07-5aea-bb01-ebd81d3e48b3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 7.2.0-tuxcare.4 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5612992f-f0d5-53de-ad17-02c4f1a9ad1f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 7.2.0-tuxcare.4 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5a961535-8f99-57c5-8542-24155ef0f943",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 7.2.0-tuxcare.4 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:45a36b46-651e-5637-b14d-6a54919a142a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 7.2.0-tuxcare.4 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:68133b96-78f0-5529-9dd7-e5670397db88",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 7.2.0-tuxcare.4 of @angular/platform-webworker. not_affected \u2014 Angular v7.2.0 is NOT AFFECTED by CVE-2026-68945. The vulnerable component (HttpTransferCache) does not exist in this version. According to patch documentation in the repository (CVE-2026-50170.patch, CVE-2026-54266.patch), the HTTP transfer-cache and client hydration features were introduced in Angular v16. Angular v7.2.0 predates this feature by many major versions. Exhaustive searches confir...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a2711c52-65c0-5de9-b7d7-95d69a042d34",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 7.2.0-tuxcare.4 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:03923215-f1db-535d-82fa-cf8f9d4e3eb0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 7.2.0-tuxcare.4 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:466e838e-6ca3-5427-877b-95c85b7e5bdb",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 7.2.0-tuxcare.4 of @angular/platform-webworker. not_affected \u2014 Angular version 7.2.0 is not affected by CVE-2026-88056. The vulnerability requires the presence of a `parseUrl` function in `packages/platform-server/src/url.ts` that uses `String.prototype.trim()` to normalize URLs, which strips Unicode whitespace and can convert validated same-origin relative URLs into cross-origin protocol-relative URLs. Version 7.2.0 does not contain the `url.ts` file; it ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9c11b873-c32d-5cc2-97f4-574401281b07",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 7.2.0-tuxcare.4 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0addec8f-9cca-5e5f-bf69-1bdd556d518e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 7.2.0-tuxcare.4 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:97c11c41-21e8-51a8-8a49-2e8bd7197690",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 7.2.0-tuxcare.4 of @angular/platform-webworker. not_affected \u2014 Angular v7.2.0 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache, hierarchical HttpClient delegation (withRequestsMadeViaParent()), and automatic HTTP response caching features that were introduced in Angular v16+. Version 7.2.0 uses NgModule-based configuration (HttpClientModule) with manual TransferState only\u2014no automatic HTTP-to-TransferState caching exists. The...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:709361ae-1d0d-5546-bbf3-223311524e1f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 7.2.0-tuxcare.4 of @angular/platform-webworker."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-webworker@7.2.0-tuxcare.4"
    }
  ]
}