{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ed88f81d-ce1b-5d4d-8eec-39ca7bfc82ab",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/router",
      "purl": "pkg:npm/%40angular/router@16.2.11-tuxcare.5",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5",
      "version": "16.2.11-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:abe8c833-6606-5627-9e33-531ec44c9bc6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 16.2.11-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:30081694-69dd-5aee-97ac-e19ce77f1bff",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.11-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:40c69341-d2db-54ee-92b4-09525034a58c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 16.2.11-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:bec736c7-068a-5cb2-9780-a3ffbfa054e7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 16.2.11-tuxcare.5 of @angular/router, and is fixed in 16.2.11-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c04c1d5b-a499-5874-a69a-57950fc2e58f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 16.2.11-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7d072661-82fb-5834-b529-36f924201b3e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 16.2.11-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:fede27e5-b3a1-5083-ac6a-6e4565820ff6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 16.2.11-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:84a53440-19ad-5a73-ace0-8f523149e693",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 16.2.11-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:979e6a9e-6f74-5af0-a087-58a5517bc56a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 16.2.11-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5b601dc8-f185-525e-a489-a9286222c191",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 16.2.11-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:19c30da7-91b9-5471-ba0c-6b08bf740de8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 16.2.11-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:dfb85f92-4148-54cf-88aa-0aa409945b57",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 16.2.11-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:679d9757-3dc3-5747-9856-76c287d096fc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 16.2.11-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2e3e7bc8-5913-5ff2-9174-d4f9495ead55",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 16.2.11-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:28a64b3d-31a2-5674-841a-20f1a12246e7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 16.2.11-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:eca6bc67-df4f-5cd6-b4da-38e99bfeeae9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 16.2.11-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:db0466da-1e1a-59bd-b995-697f607df8a2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 16.2.11-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:db4e738b-7308-5d24-beeb-1a8bdd550f71",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 16.2.11-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:43847147-d7ef-5fb9-b7b7-4eec47c04fdb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 16.2.11-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a21e44c2-be92-5221-8d0b-ed69c1752014",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 16.2.11-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8987a273-75d7-58a2-9a3b-9f5a9461d568",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 16.2.11-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:056cf38f-f6c0-5b1c-8046-38ddad9e6526",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 16.2.11-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3b71354d-eef4-54de-828f-f02b62ab3d0b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 16.2.11-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a58baa14-3730-5a29-85b8-7e83f8429e67",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 16.2.11-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f27eaf18-b8b0-5fe7-9dac-6b0f4b9bfe0d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 16.2.11-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a69c4548-1402-5930-8a89-9f439895c8f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 16.2.11-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e9d3dc53-adb3-5b11-a8ab-74494563424a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.11-tuxcare.5 of @angular/router. not_affected \u2014 Angular 16.2.11-tuxcare.2 is NOT affected by CVE-2026-88056. The vulnerability requires WHATWG URL validation combined with String.prototype.trim() on URLs during SSR, creating a discrepancy that enables SSRF. While the target uses WHATWG URL parsing (backported in commit c03fbfd7cc for CVE-2026-50168), it does NOT call String.prototype.trim() on URLs. The attack chain is broken at the trim() s...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f69cee8b-5347-5735-b394-27f88d090273",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 16.2.11-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:950c4d67-c880-534f-a188-12fa049ba960",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 16.2.11-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d7d56cb6-d1f7-52af-8f7d-95c7809845bc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 16.2.11-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1aa74641-562b-5114-a7a7-c2e416c1b752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 16.2.11-tuxcare.5 of @angular/router."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/router@16.2.11-tuxcare.5"
    }
  ]
}