{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3bf1254d-5b29-5e96-898a-10de550b0019",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/elements",
      "purl": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5",
      "version": "7.2.0-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a4b4527a-6ca5-5fe7-b042-b5d74ff4c65e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 7.2.0-tuxcare.5 of @angular/elements."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a66466fd-0017-596b-9b96-4c1ca7038d93",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 7.2.0-tuxcare.5 of @angular/elements."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:209f97cc-8d50-53a9-a074-d18cb08ae1cd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 7.2.0-tuxcare.5 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6c86e2f4-66fe-5655-96fc-b0b74f2b00e2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 7.2.0-tuxcare.5 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:781d63a0-23cb-52a7-89f1-41363ce22b21",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 7.2.0-tuxcare.5 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9b56161c-5c8d-5da9-a095-f1e6384e9dc7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 7.2.0-tuxcare.5 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6524b5c8-d02c-5058-b6b3-7dc16cd7357f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 7.2.0-tuxcare.5 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7d112798-97bd-52d4-b8f3-d65b7f2c840d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 7.2.0-tuxcare.5 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e5f0509e-8e07-55d6-943d-897e168d0271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 7.2.0-tuxcare.5 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:638d4f8b-5649-5210-909d-b3edad353716",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 7.2.0-tuxcare.5 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1c02351f-c59d-56de-b1da-8396df8c69e1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 7.2.0-tuxcare.5 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e150a42d-e38e-5bca-a987-8be1288128f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 7.2.0-tuxcare.5 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b7f37616-2244-5bff-a6de-63014b23323e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 7.2.0-tuxcare.5 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c60e9c47-6990-53a7-ae0e-7d3714858771",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 7.2.0-tuxcare.5 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7a910a7c-c628-544e-b982-23ab2e76dc92",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 7.2.0-tuxcare.5 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f1634d60-b341-5df0-9a3f-3c265ffd3436",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 7.2.0-tuxcare.5 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7fa372cd-017f-5aa0-9425-5930df55350f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 7.2.0-tuxcare.5 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1558edef-bcf0-502c-bf14-6c8068ac6145",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 7.2.0-tuxcare.5 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5b128374-fd04-5e30-89a6-60fb2d798182",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 7.2.0-tuxcare.5 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:40565432-a495-5b04-93ee-e2afb1d4cb9e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 7.2.0-tuxcare.5 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2f6b48aa-c71c-505e-8c5f-a6613bc3e658",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 7.2.0-tuxcare.5 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5d71006e-098f-5481-a5bc-19c55b10df50",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 7.2.0-tuxcare.5 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ed81322f-4830-592f-9b70-3940cedf3489",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 7.2.0-tuxcare.5 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8ee80080-8eae-5427-b376-d9c415448c5d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 7.2.0-tuxcare.5 of @angular/elements. not_affected \u2014 Angular v7.2.0 is NOT AFFECTED by CVE-2026-68945. The vulnerable component (HttpTransferCache) does not exist in this version. According to patch documentation in the repository (CVE-2026-50170.patch, CVE-2026-54266.patch), the HTTP transfer-cache and client hydration features were introduced in Angular v16. Angular v7.2.0 predates this feature by many major versions. Exhaustive searches confir...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:53a1e349-aa25-5c30-a2d8-25caa1096157",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 7.2.0-tuxcare.5 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c5dfc737-430b-57fd-bb07-687193348107",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 7.2.0-tuxcare.5 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:33c35d6f-cce4-5037-b4a3-b0c71f93578b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 7.2.0-tuxcare.5 of @angular/elements. not_affected \u2014 Angular version 7.2.0 is not affected by CVE-2026-88056. The vulnerability requires the presence of a `parseUrl` function in `packages/platform-server/src/url.ts` that uses `String.prototype.trim()` to normalize URLs, which strips Unicode whitespace and can convert validated same-origin relative URLs into cross-origin protocol-relative URLs. Version 7.2.0 does not contain the `url.ts` file; it ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4582bd16-0a78-5339-81a0-109e2925982f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 7.2.0-tuxcare.5 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6a33ee62-69df-59d1-b268-94228b86339d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 7.2.0-tuxcare.5 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f2b9aa54-cae5-5fb0-9928-ffa1e5c79f33",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 7.2.0-tuxcare.5 of @angular/elements. not_affected \u2014 Angular v7.2.0 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache, hierarchical HttpClient delegation (withRequestsMadeViaParent()), and automatic HTTP response caching features that were introduced in Angular v16+. Version 7.2.0 uses NgModule-based configuration (HttpClientModule) with manual TransferState only\u2014no automatic HTTP-to-TransferState caching exists. The...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1968fa61-c4dd-59ae-818c-b353d15f8115",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 7.2.0-tuxcare.5 of @angular/elements."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.5"
    }
  ]
}