{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:824bc3ce-30ee-587a-8738-0eeaf66f536c",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/router",
      "purl": "pkg:npm/%40angular/router@19.2.21-tuxcare.7",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/router@19.2.21-tuxcare.7",
      "version": "19.2.21-tuxcare.7",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@19.2.21-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:62b3844b-1d41-5a1e-a231-1f7f447f2aa6",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-27970 does not affect version 19.2.21-tuxcare.7 of @angular/router. already_fixed \u2014 The target repository (Angular 19.2.21-tuxcare.4) already contains the fix for CVE-2026-27970. The vulnerability (XSS via unsanitized HTML attributes in ICU message translations) has been addressed by TuxCare in prior backports. The defense mechanism in packages/core/src/render3/i18n/i18n_parse.ts lines 829-843 implements the same attribute allowlist validation as the vendor patch, blocking URI...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@19.2.21-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:2d3c2a75-8317-5f1f-a6e3-5cbb86e3aa04",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 19.2.21-tuxcare.7 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@19.2.21-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:811d9fc8-609b-540d-b05a-c920e9ba3357",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 19.2.21-tuxcare.7 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@19.2.21-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:d20a03a5-eaca-552a-8c19-bbb439adc5a4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 19.2.21-tuxcare.7 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@19.2.21-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:3ef0e60d-081a-526c-b08f-82f797e92051",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 19.2.21-tuxcare.7 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@19.2.21-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:154c039a-34d4-52a1-bd40-cd950c171da1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 19.2.21-tuxcare.7 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@19.2.21-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:6d15545b-a4fa-5b26-8fee-349f8826f549",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 19.2.21-tuxcare.7 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@19.2.21-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:3ff7bb0f-b19f-5995-856a-13be1886cdd7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 19.2.21-tuxcare.7 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@19.2.21-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:2cfbc00d-4d15-58bf-ae1c-5aa0d99dfbdd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 19.2.21-tuxcare.7 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@19.2.21-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:ec2632da-e2e2-5e22-b083-f77ef2071af1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 19.2.21-tuxcare.7 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@19.2.21-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:3ad622ff-b679-5a92-8aaf-a6c0ed0940c5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 19.2.21-tuxcare.7 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@19.2.21-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:cfefa1a2-cbc6-573f-a398-28efd22c1929",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 19.2.21-tuxcare.7 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@19.2.21-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:40df7025-4f32-5e7d-8fc5-58b394c63e99",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 19.2.21-tuxcare.7 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@19.2.21-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:b77bcd1a-79ff-5d9c-8bf3-6bc1cda03872",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 19.2.21-tuxcare.7 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@19.2.21-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:83bb8694-7167-547f-b08a-87ad3a2af4d2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 19.2.21-tuxcare.7 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@19.2.21-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:2ce7e8ef-3b36-5585-8c21-ab11fdab6faa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 19.2.21-tuxcare.7 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@19.2.21-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:339071e5-8b4d-5c3d-8b4e-91bfd75e257e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 19.2.21-tuxcare.7 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@19.2.21-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:3b4bdaa4-ebd8-5fc7-90b0-dfd5376b7301",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 19.2.21-tuxcare.7 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@19.2.21-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:e177d573-eccf-55db-be9f-48350e4b5019",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 19.2.21-tuxcare.7 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@19.2.21-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:77be17ca-a532-5909-8a65-4bac67d6f53d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 19.2.21-tuxcare.7 of @angular/router. not_affected \u2014 CVE-2026-88056 does not affect this Angular v19.2.21-tuxcare.5 target. The CVE describes a vulnerability where `String.prototype.trim()` strips Unicode whitespace (U+00A0, U+FEFF) from URLs during SSR, converting same-origin relative paths into cross-origin protocol-relative URLs that leak credentials. The v19.2.x branch uses a simpler URL resolution implementation created by TuxCare (commit 81...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@19.2.21-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:3c376f52-fe46-5fa8-b1c6-9b477c1e042f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 19.2.21-tuxcare.7 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@19.2.21-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:135292e0-09c9-5782-8c1a-878b96379e1f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 19.2.21-tuxcare.7 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@19.2.21-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:33aa05b0-1ce3-5941-a3db-d93f56489638",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 19.2.21-tuxcare.7 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@19.2.21-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:a34c0799-2c75-5e23-a11d-208eea07f37d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 19.2.21-tuxcare.7 of @angular/router."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/router@19.2.21-tuxcare.7"
    }
  ]
}