{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1ac88ee2-9431-5164-9796-7b044730b2e0",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/router",
      "purl": "pkg:npm/%40angular/router@7.2.0-tuxcare.4",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4",
      "version": "7.2.0-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9557d0cb-3dac-50de-a819-d9f870f29f31",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 7.2.0-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:54b7b594-4002-5448-a0de-6c6c6ad0319e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 7.2.0-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f025d648-2e9d-5a0d-978a-8c0d48622a1a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 7.2.0-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:98807247-c703-55b7-a546-d665b8514653",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-101895 does not affect version 7.2.0-tuxcare.4 of @angular/router. not_affected \u2014 CVE-2026-101895 affects domino's HTML parser (lib/HTMLParser.js), which is declared as a dependency in Angular's package.json (domino@2.1.0) but is NOT vendored or present in this repository's source tree. While Angular SSR applications using this version ARE exploitable (user input via [innerHTML] bindings reaches domino's vulnerable parser without DOCTYPE validation), the TARGET REPOSITORY do...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f8d1dced-6aa8-5fcc-ba0e-768dd51349c6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 7.2.0-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5f4fd005-8590-575d-9535-6fb2b66a21df",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 7.2.0-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6cc16589-13da-579c-a190-d6b4b0b6a23a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 7.2.0-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5ec87c23-d78c-5217-a2fe-d2ef2ddf5990",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 7.2.0-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:94055db4-d389-598e-a6df-51ab9705e5ce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 7.2.0-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9928dfd1-8472-511a-9942-feb1505c50d7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 7.2.0-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b9b9e3d1-53ca-5af7-98db-b83818db2330",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 7.2.0-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:26aa5131-1c1b-55d7-b237-5eaef32e6a91",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 7.2.0-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:dd22afc6-1c27-572d-9df8-e54cf478fd32",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 7.2.0-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:46e5e41f-fc93-5d2b-8f02-c677e845806d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 7.2.0-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:057e8133-b533-52fe-af5f-b160a1b18aa2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 7.2.0-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:fb3a2378-a326-59eb-982f-c8bd706a8473",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 7.2.0-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:aa2aea33-7346-554f-9376-1d119ebc9017",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 7.2.0-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0b9ceead-0db5-5536-a1e9-098a420e50b3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 7.2.0-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:916969d4-67dd-570a-8fdb-ef27628da31b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 7.2.0-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:845d731d-16c6-5aa1-98f5-52b29cfa9535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 7.2.0-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f5d17b0b-8383-56f3-9edb-e8b419b4ba1f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 7.2.0-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:133e504a-c010-502a-81cd-e49d4fddfd53",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 7.2.0-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:230a79ba-b0dc-58ae-a4e1-e3c10b199fc3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 7.2.0-tuxcare.4 of @angular/router. not_affected \u2014 Angular v7.2.0 is NOT AFFECTED by CVE-2026-68945. The vulnerable component (HttpTransferCache) does not exist in this version. According to patch documentation in the repository (CVE-2026-50170.patch, CVE-2026-54266.patch), the HTTP transfer-cache and client hydration features were introduced in Angular v16. Angular v7.2.0 predates this feature by many major versions. Exhaustive searches confir...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b9fa8400-1468-54d4-8dd3-2e678ea5787a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 7.2.0-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f304183a-80b2-537e-80f7-1f2b9358c84b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 7.2.0-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5ff58777-44bd-54ae-a5f6-e4fd723f3e23",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 7.2.0-tuxcare.4 of @angular/router. not_affected \u2014 Angular version 7.2.0 is not affected by CVE-2026-88056. The vulnerability requires the presence of a `parseUrl` function in `packages/platform-server/src/url.ts` that uses `String.prototype.trim()` to normalize URLs, which strips Unicode whitespace and can convert validated same-origin relative URLs into cross-origin protocol-relative URLs. Version 7.2.0 does not contain the `url.ts` file; it ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:52c8447e-0e8b-554a-be41-fbcdb439cc30",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 7.2.0-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1de34dc6-6fd5-505e-9bcb-4f8625c78d85",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 7.2.0-tuxcare.4 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:2a88146d-0c44-573d-a072-d3849af9a711",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 7.2.0-tuxcare.4 of @angular/router. not_affected \u2014 Angular v7.2.0 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache, hierarchical HttpClient delegation (withRequestsMadeViaParent()), and automatic HTTP response caching features that were introduced in Angular v16+. Version 7.2.0 uses NgModule-based configuration (HttpClientModule) with manual TransferState only\u2014no automatic HTTP-to-TransferState caching exists. The...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:87fd2544-12e3-5277-b2a0-e63a247dd2e9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 7.2.0-tuxcare.4 of @angular/router."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/router@7.2.0-tuxcare.4"
    }
  ]
}