{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:da32b274-5a18-5c56-904d-22af6508a2c3",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/bazel",
      "purl": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5",
      "version": "7.2.0-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:723d49d8-43a8-56f4-80b1-842709206f01",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 7.2.0-tuxcare.5 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:477c88a1-5434-574d-8a5b-b5a2865bec21",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 7.2.0-tuxcare.5 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:28cf8302-f857-5ed9-b374-ae826f34d69a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 7.2.0-tuxcare.5 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e19aa26e-345b-5f5b-b59d-253edfd62e0a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 7.2.0-tuxcare.5 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b7dfbc29-ab15-576e-85dd-5dfebf13fbab",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 7.2.0-tuxcare.5 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:132d3c1a-68aa-570f-8a38-0efcd85d8493",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 7.2.0-tuxcare.5 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4f83bba1-9b49-549a-8bd1-0f16a571ab55",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 7.2.0-tuxcare.5 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:26eca2e6-e526-525b-a62e-af516fdf875f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 7.2.0-tuxcare.5 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:41b37a52-d315-505b-94c1-4244ca15b946",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 7.2.0-tuxcare.5 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:815a2d51-cb65-5ec6-8bdc-d0dc41d1a464",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 7.2.0-tuxcare.5 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:30b3d99d-ac29-5411-a4cd-8f0559be114b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 7.2.0-tuxcare.5 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a063281b-2d78-52e6-a5c1-ac9b117634a3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 7.2.0-tuxcare.5 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8c59aac6-d7a4-50ec-b27d-bb1f9b2aa0a3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 7.2.0-tuxcare.5 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5d9e8b6b-c840-5c0c-a38c-3c19587a31d0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 7.2.0-tuxcare.5 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2f8898e6-2186-5406-bd5f-28667ceddd49",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 7.2.0-tuxcare.5 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:056b157a-ff7e-5cc9-b975-afe49f036971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 7.2.0-tuxcare.5 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:eb49a145-2ef5-54a0-91c6-1f0bc00d6d6b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 7.2.0-tuxcare.5 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a16e1bb5-63fb-5eaa-b347-77b9fcb70e07",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 7.2.0-tuxcare.5 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:116589d0-d0d4-5fa2-ba79-42dbc966b2c7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 7.2.0-tuxcare.5 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9319e415-1708-5bc8-a1cc-f63051dd6cc4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 7.2.0-tuxcare.5 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d2feb628-967a-55ec-97d2-65c078af515e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 7.2.0-tuxcare.5 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0f4250fa-457b-5f7e-af4d-dd7b426064e4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 7.2.0-tuxcare.5 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:533c7e45-37c0-52be-ad5a-445cebfef133",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 7.2.0-tuxcare.5 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:832d835b-23d7-5258-93c8-5abff47be45f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 7.2.0-tuxcare.5 of @angular/bazel. not_affected \u2014 Angular v7.2.0 is NOT AFFECTED by CVE-2026-68945. The vulnerable component (HttpTransferCache) does not exist in this version. According to patch documentation in the repository (CVE-2026-50170.patch, CVE-2026-54266.patch), the HTTP transfer-cache and client hydration features were introduced in Angular v16. Angular v7.2.0 predates this feature by many major versions. Exhaustive searches confir...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f1722e87-ed00-5649-a20f-3b1d35bd0c3b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 7.2.0-tuxcare.5 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:aed02166-8189-5124-b143-5d0f6466cfdf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 7.2.0-tuxcare.5 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7fc24b51-f4e3-5a9f-90ac-e7bd6a61d2cd",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 7.2.0-tuxcare.5 of @angular/bazel. not_affected \u2014 Angular version 7.2.0 is not affected by CVE-2026-88056. The vulnerability requires the presence of a `parseUrl` function in `packages/platform-server/src/url.ts` that uses `String.prototype.trim()` to normalize URLs, which strips Unicode whitespace and can convert validated same-origin relative URLs into cross-origin protocol-relative URLs. Version 7.2.0 does not contain the `url.ts` file; it ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f2befd21-705e-5912-82d8-543ce8fb43f0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 7.2.0-tuxcare.5 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:bb99299e-8341-5c01-ad0e-2c457ddbec75",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 7.2.0-tuxcare.5 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ac39fb5e-4ff7-5d7b-92eb-82d8663f7f4a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 7.2.0-tuxcare.5 of @angular/bazel. not_affected \u2014 Angular v7.2.0 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache, hierarchical HttpClient delegation (withRequestsMadeViaParent()), and automatic HTTP response caching features that were introduced in Angular v16+. Version 7.2.0 uses NgModule-based configuration (HttpClientModule) with manual TransferState only\u2014no automatic HTTP-to-TransferState caching exists. The...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6225207a-5493-5db4-a6af-7b7a1b0c4b80",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 7.2.0-tuxcare.5 of @angular/bazel."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/bazel@7.2.0-tuxcare.5"
    }
  ]
}