{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9e42755b-fb08-5441-85f5-00db964124bd",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/common",
      "purl": "pkg:npm/%40angular/common@7.2.0-tuxcare.5",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5",
      "version": "7.2.0-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8caa6259-504b-5cab-843d-89cbf22e42d2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 7.2.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:969ef154-7259-57b3-a6d8-61ab28a727b6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 7.2.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:07789b3b-6ab3-5334-8713-528449d5efad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 7.2.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:70976919-3afe-5107-af78-c9c84679a704",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 7.2.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:96009d1a-e577-50c7-bffd-a5537858051e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 7.2.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4ad3c1e2-fc8d-54b0-9b47-f9c292ab470c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 7.2.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a6d3b43a-7a76-5b50-bf13-e17b7a1d4453",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 7.2.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ea8c43a8-a09a-5216-aec9-071648380977",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 7.2.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:243cbbf5-8155-572e-a2da-2b4976e61925",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 7.2.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5ad424fe-10ba-5dfa-a284-81f76673aca1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 7.2.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:14c68bef-2a27-59a6-9e57-6dc40227484f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 7.2.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:84c3c8a2-88a1-5765-a087-eb1525b6ceb3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 7.2.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f19b2a5f-53ce-5022-92f0-ad61cea1c09c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 7.2.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:aaf4c3f8-35d8-5435-8f33-076732236564",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 7.2.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:809377df-e0d8-5727-96e1-2c5a69f0817f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 7.2.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9cf06ea6-3631-566a-bade-447cb15a5bf4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 7.2.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ce2fd70e-20e2-5dfc-87a4-1460f22cf7e9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 7.2.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2c273448-dd53-51a0-8428-001ec793b08c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 7.2.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c68af29f-ba28-50e7-acdf-289a0309d687",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 7.2.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5ea85c38-1917-52f5-9db7-f3fc0c3876e6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 7.2.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:04dc245a-7dd3-51c7-a94b-287fe0f3e4a0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 7.2.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1dfab93b-a97e-5c58-afcf-175a779c82a4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 7.2.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ab3cdddf-7766-54cd-b82d-80233b2ac68d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 7.2.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2555d083-3cb0-54a6-8505-e1a22e529200",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 7.2.0-tuxcare.5 of @angular/common. not_affected \u2014 Angular v7.2.0 is NOT AFFECTED by CVE-2026-68945. The vulnerable component (HttpTransferCache) does not exist in this version. According to patch documentation in the repository (CVE-2026-50170.patch, CVE-2026-54266.patch), the HTTP transfer-cache and client hydration features were introduced in Angular v16. Angular v7.2.0 predates this feature by many major versions. Exhaustive searches confir...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c2bb992d-30e4-5329-a806-b9c47f473c42",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 7.2.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:45ef70f3-589d-5e36-833b-41f784d04028",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 7.2.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a0fe5d68-9ea7-5d5b-9a65-bb6b2c491c51",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 7.2.0-tuxcare.5 of @angular/common. not_affected \u2014 Angular version 7.2.0 is not affected by CVE-2026-88056. The vulnerability requires the presence of a `parseUrl` function in `packages/platform-server/src/url.ts` that uses `String.prototype.trim()` to normalize URLs, which strips Unicode whitespace and can convert validated same-origin relative URLs into cross-origin protocol-relative URLs. Version 7.2.0 does not contain the `url.ts` file; it ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:43f75f19-b4a9-597b-9537-c22d37a3ed94",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 7.2.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0916ba92-1585-5a87-b05b-f0d49f8676d8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 7.2.0-tuxcare.5 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:bb3950a8-407d-5257-984c-26c0cffd40fb",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 7.2.0-tuxcare.5 of @angular/common. not_affected \u2014 Angular v7.2.0 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache, hierarchical HttpClient delegation (withRequestsMadeViaParent()), and automatic HTTP response caching features that were introduced in Angular v16+. Version 7.2.0 uses NgModule-based configuration (HttpClientModule) with manual TransferState only\u2014no automatic HTTP-to-TransferState caching exists. The...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1b9fd0dc-c5f6-5c8b-ab4d-60518f97f115",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 7.2.0-tuxcare.5 of @angular/common."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/common@7.2.0-tuxcare.5"
    }
  ]
}