{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:47d70713-ce11-5901-80ab-2f7b21c1a02e",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/router",
      "purl": "pkg:npm/%40angular/router@16.2.11-tuxcare.4",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4",
      "version": "16.2.11-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d3bc7091-80c9-53b9-bb71-32c040d22cc3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 16.2.11-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:67ca7ed9-a6ed-5a41-8e92-89f5e024d5c5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.11-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:75c84519-d015-5a01-982c-900537c87aa4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 16.2.11-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a8c489af-3a00-5146-a74b-83be0d6a84a4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 16.2.11-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d05d02cb-7e22-5974-94d5-cebe625f57fd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 16.2.11-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d3c6b5db-95d1-52b4-bc81-da3fee53537e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 16.2.11-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a91634e3-6fb6-5ecd-a14a-2e51e8332337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 16.2.11-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:513a6ba9-5f16-5a78-811a-787a3c414063",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 16.2.11-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:bb0d3a7b-241e-5c03-ba56-5898f2b8a628",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 16.2.11-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:343a8c10-a4fb-5b2b-a605-4b04fa5f3671",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 16.2.11-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0326d9de-3939-5b76-b67c-99c6501a14bb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 16.2.11-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:626654d2-bb59-50bf-aa9a-aa7916e91ff3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 16.2.11-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a77ddb97-bb35-5433-a5aa-3dafdc7dad45",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 16.2.11-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f3ed0d51-4204-5775-bea8-ef3b2f3a1e3f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 16.2.11-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:73274f44-722d-5a85-a23c-1c34473313ec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 16.2.11-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3426bb7b-03f9-52b5-8878-fdd8dc661e30",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 16.2.11-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d6074939-7608-55df-9fa4-b05bbfead39f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 16.2.11-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7188d703-f65a-5b25-816f-07b9924d7a95",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 16.2.11-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:772e3f0e-cb1a-5c2c-89d6-104aa8bcd0f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 16.2.11-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:01ad1347-14ae-5956-9079-9924a798cc3f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 16.2.11-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:802fb209-ca8d-5db5-937e-d1b10ebe4d0f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 16.2.11-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:fa6b1926-27a5-58f1-a894-eb2376503fda",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 16.2.11-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:850db4c7-6ef4-5fad-bd09-de4319cbf3d5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 16.2.11-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3fd4e66f-da63-5030-9e25-2092398e6c1e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 16.2.11-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:257ffd73-843d-5756-8d69-8ffa649771fe",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.11-tuxcare.4 of @angular/router. not_affected \u2014 Angular 16.2.11-tuxcare.2 is NOT affected by CVE-2026-88056. The vulnerability requires WHATWG URL validation combined with String.prototype.trim() on URLs during SSR, creating a discrepancy that enables SSRF. While the target uses WHATWG URL parsing (backported in commit c03fbfd7cc for CVE-2026-50168), it does NOT call String.prototype.trim() on URLs. The attack chain is broken at the trim() s...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c9e6dd5e-82a6-5296-bf49-e8631fff89b2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 16.2.11-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:02479027-096e-5afe-9b6b-6e0c0fe92fe5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 16.2.11-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:05b0f688-d3e6-5943-9483-1f4fa99186a4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 16.2.11-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9dd451e4-43a3-5f9f-b1f5-39aeb154705c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 16.2.11-tuxcare.4 of @angular/router."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.4"
    }
  ]
}