{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6855de70-ce3e-5ba3-9fcd-20941bcaca61",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/router",
      "purl": "pkg:npm/%40angular/router@12.2.17-tuxcare.12",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12",
      "version": "12.2.17-tuxcare.12",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:d3c48749-555e-5721-acf8-eba67b167512",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 12.2.17-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:d405a491-bb03-56a5-aa02-97378284c1c7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 12.2.17-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:68a2a8ab-64e9-54ba-98d3-cab652c0bb5d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 12.2.17-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:a1d88384-5ad6-573c-bf5a-6b4949558381",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 12.2.17-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:1326b25f-eb09-55c9-af3f-a1b3b500fe45",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 12.2.17-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:8d2b12b5-7917-5a30-9b17-b16baf39f2b7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 12.2.17-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:1594ac6e-c07b-56bb-a911-6c7e5f888713",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 12.2.17-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:9450b7e1-7a11-5d6f-b13f-935ac7b0d8f6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 12.2.17-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:4bd58eef-4056-545f-b507-1a5865846912",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 12.2.17-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:7a352b4e-adc5-5507-817b-9547bd28d1ef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 12.2.17-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:2295b2ad-f563-5ad1-a6ec-e58bc37f092c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 12.2.17-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:dae89d31-b192-5397-b3d1-891bc8fe613a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 12.2.17-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:394a1d8f-07fd-5639-9733-046ee05efbfe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 12.2.17-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:ab1efd8a-3afd-522f-836e-e76c1dc000ca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 12.2.17-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:7b92f8ca-354f-5b4b-a1e5-783e21891fa6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 12.2.17-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:5eb86f64-c95a-5d92-945e-b98e01f9164b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 12.2.17-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:aed35872-3c80-5dbf-9afb-4986decca590",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 12.2.17-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:bec161a3-eb69-59d3-8d20-a11a245e53ea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 12.2.17-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:29c57067-265e-5593-9ae3-ffc1b61cdc5a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 12.2.17-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:6e6cceb8-8f1f-5641-b7e7-a0270ca1581b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 12.2.17-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:fbec0486-b90d-53da-8540-47261e20861e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 12.2.17-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:5766f34e-22af-5b9c-bd97-fe72b87c912d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 12.2.17-tuxcare.12 of @angular/router. not_affected \u2014 Angular 12.2.17 does not contain the HttpTransferCache feature affected by CVE-2026-68945. HttpTransferCache, which caches HTTP requests during Server-Side Rendering (SSR), was first introduced in Angular 16.0.0\u2014approximately 4 major versions after the target version. The vulnerability concerns cache-key collision when repeated HTTP parameters are serialized, but since the entire HttpTransferCa...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:bbdc33cf-2bb1-5c06-83d4-c0c7c9bc9be0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 12.2.17-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:dc56d261-8eff-5831-a3a4-927899602f38",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 12.2.17-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:1723e7bb-1426-5946-9914-4e12071c251a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88056 is fixed in version 12.2.17-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:1d3b0848-e5c4-5f3a-a959-505f496b3e74",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 12.2.17-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:70330880-6e20-5a12-aeba-e919505d300a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 12.2.17-tuxcare.12 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:12dff94b-53ab-5ba6-8aa5-3b14ae65e8dd",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 12.2.17-tuxcare.12 of @angular/router. not_affected \u2014 Angular 12.2.17-tuxcare.9 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, withRequestsMadeViaParent(), and provideClientHydration() features which were introduced in Angular 16.0.0. This version uses the older module-based HttpClientModule system and lacks the entire SSR hydration transfer-cache infrastructure. The vulnerable code pattern described in the CVE do...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:c85d1122-54de-5ddf-887c-47183bae582b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 12.2.17-tuxcare.12 of @angular/router."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/router@12.2.17-tuxcare.12"
    }
  ]
}