{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:843da6aa-2fdf-588d-bfc9-a83f603bff55",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/core",
      "purl": "pkg:npm/%40angular/core@7.2.16-tuxcare.13",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13",
      "version": "7.2.16-tuxcare.13",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:c8960454-6065-5ca0-af55-200fe5c16c11",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 7.2.16-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:ad6c62ed-ea63-5137-a0f7-b14194517397",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 7.2.16-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:3c3332f7-fdff-508b-88a6-392d2782794d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 7.2.16-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:adfbaa8a-292b-50b7-a49b-a4efd5a4c730",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 7.2.16-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:a1772144-be82-5250-a28a-19ba33c9d6c0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 7.2.16-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:3e7b2462-b1dd-52bb-abe0-a1f74b63265c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 7.2.16-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:3c5894e2-a0df-56ed-a393-07496e592f63",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 7.2.16-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:1ab0d8c5-294f-5cd8-b9ef-bab658d9d87a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 7.2.16-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:b6632edf-08b9-55c6-a7b6-64a02b74f6a9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 7.2.16-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:319fd47c-b517-58a9-a14b-f5f54a794bae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 7.2.16-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:20c7c5b7-25a6-5910-8969-6b15b90e7241",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 7.2.16-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:efe6f6a5-297e-5c2c-ae65-bf5d59fd0c4c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 7.2.16-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:9775bccc-f188-5ef7-aa03-440c9585c0db",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 7.2.16-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:117bcfb0-8078-5230-89c1-6d861c8116f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 7.2.16-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:a7b66284-20e8-5f71-8878-46f0b75580c9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 7.2.16-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:02a65dc3-81a4-54c2-a07e-0f8fc64fcbd5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 7.2.16-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:e393c99c-82be-5dcf-a317-87989680657c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 7.2.16-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:b1f1a6db-5482-5d29-bbcc-8f52dc7a0724",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 7.2.16-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:ecc94e72-1c8f-5600-8382-817a5a9a2e2e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 7.2.16-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:ed9f6ae5-3bde-5a1f-b0a3-ba3bd3e05445",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 7.2.16-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:bf04edf7-c1ac-54fd-b5dc-443c1e8d0fa1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 7.2.16-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:2079a473-166a-5ea7-a248-b7d006cda509",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 7.2.16-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:926cb791-e98a-5f28-b080-39c8b609e776",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 7.2.16-tuxcare.13 of @angular/core. not_affected \u2014 Angular 7.2.16 is not affected by CVE-2026-68945. The vulnerability concerns HttpTransferCache's cache key generation logic that treats repeated HTTP parameters (`?role=user&role=admin`) and comma-separated values (`?role=user,admin`) as identical, causing cache key collisions. However, the HttpTransferCache feature does not exist in version 7.2.16\u2014it was introduced in Angular v16. While v7.2.1...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:c81960d4-e9ba-5991-8ba5-96db5eb9f435",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 7.2.16-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:c3786628-45e2-5e94-9f3d-4c4d0ff8b2f6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 7.2.16-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:2985dc58-9722-5b20-a948-893096dc7134",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 7.2.16-tuxcare.13 of @angular/core. not_affected \u2014 Angular 7.2.16 is not affected by CVE-2026-88056. The vulnerability requires a String.prototype.trim() call on URLs during server-side rendering that strips Unicode whitespace characters, converting same-origin relative URLs into cross-origin protocol-relative URLs. This vulnerable code pattern does not exist in Angular 7.2.16. The CVE describes a vulnerability introduced in later Angular versi...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:13b44aeb-9fa4-5168-95d6-148e0880b94a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88057 does not affect version 7.2.16-tuxcare.13 of @angular/core. not_affected \u2014 Angular 7.2.16 is not affected by CVE-2026-88057. The vulnerability exists in the Ivy compiler's template pipeline (introduced in Angular 9+), which does not exist in this version. Angular 7.2.16 uses View Engine, where the SecurityContext determination for directive host bindings correctly uses the concrete host element name (`element.name`) rather than the directive's selector. The exploitati...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:3ca18a71-c47e-5a88-a8da-05c2617cc683",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 7.2.16-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:373d6d5b-503c-55b9-96de-148242071941",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 7.2.16-tuxcare.13 of @angular/core. not_affected \u2014 Angular 7.2.16 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, withRequestsMadeViaParent(), and client hydration features that were introduced in Angular v16+. Angular 7.2.16 predates these features by approximately 7 major versions. The codebase contains only legacy TransferState (manual key-value store) and NgModule-based HttpClient (no hierarchical delegation...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:03d657ba-eb25-5dff-a8ad-4069953703b9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 7.2.16-tuxcare.13 of @angular/core."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/core@7.2.16-tuxcare.13"
    }
  ]
}