{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f0e791e0-f37a-5ed1-9676-fea472432bc4",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/router",
      "purl": "pkg:npm/%40angular/router@17.3.12-tuxcare.18",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18",
      "version": "17.3.12-tuxcare.18",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:58d1cf41-1435-544b-a81b-bc9cc98bac70",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.3.12-tuxcare.18 of @angular/router."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:15f00919-5e0c-5ad3-90d6-c794b29840d1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.3.12-tuxcare.18 of @angular/router."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:43dbe6f6-6cc0-51bc-a5c0-e37bad0f83ec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.3.12-tuxcare.18 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:950e9c66-6b47-52d3-a825-623e1a535020",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 17.3.12-tuxcare.18 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:7bff5a14-da6d-5964-8fea-6a2024c15f28",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 17.3.12-tuxcare.18 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:1ec6c2d9-c63e-574d-933c-1a44fb406499",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.3.12-tuxcare.18 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:5fec522f-0620-5048-b896-5eceba366744",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.3.12-tuxcare.18 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:96245345-b388-5182-bf8f-6933874281f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.3.12-tuxcare.18 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:759d0d10-e59c-545d-a01c-22cc12308fc8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.3.12-tuxcare.18 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:a44a3c58-f4dc-5782-8c98-cfaca5c97c26",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.3.12-tuxcare.18 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:8b55845e-22b8-5749-9b29-d00b856a1f2c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.3.12-tuxcare.18 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:0f923dee-a8ac-5bb1-8430-df20b2f20b1f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.3.12-tuxcare.18 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:1011ee33-d1ae-55b7-8fd5-2f6cb5e7d49b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.3.12-tuxcare.18 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:d54a074e-3032-54e1-a129-2d32ffe71446",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.3.12-tuxcare.18 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:3f912393-8377-5f4a-ad85-3e929c52591f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.3.12-tuxcare.18 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:633a6659-032e-5b87-b727-6688a81196f9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.3.12-tuxcare.18 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:332e14b9-235e-55ad-bda5-0458e3eddb13",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.3.12-tuxcare.18 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:6fa984ec-e18a-553a-b560-cfc85b288aec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.3.12-tuxcare.18 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:34b54f0d-4442-554f-afae-fc2eacf07463",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.3.12-tuxcare.18 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:4cc0d8e1-740b-5b6b-b882-43a77d86fd8a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 17.3.12-tuxcare.18 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:636011e9-3870-55af-bd10-2546af3bf6f3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.3.12-tuxcare.18 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:d8052e10-e1f9-5208-9cdf-b8914cf76615",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.3.12-tuxcare.18 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:838406a3-1448-5a7c-950a-eb76ce50c3fb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.3.12-tuxcare.18 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:9626ab56-4322-50cc-b061-cc2246dcf724",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 17.3.12-tuxcare.18 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:610ce7f4-886a-5266-a70a-689d4254f1f1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 17.3.12-tuxcare.18 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:6b9773c4-96d7-5638-96ea-385bf1a7a6a6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 17.3.12-tuxcare.18 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:b04f1663-8f9e-5a30-8eca-44f3251297d8",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.3.12-tuxcare.18 of @angular/router. not_affected \u2014 Version 17.3.12 is not affected by CVE-2026-88056. The vulnerability involves String.prototype.trim() being applied during URL resolution in Angular's platform-server, converting validated same-origin URLs with Unicode whitespace into cross-origin protocol-relative URLs, leading to SSRF. This vulnerable code pattern was introduced in newer Angular versions (v20+) and does not exist in version 1...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:6ae3734a-0799-5219-abd7-82fc128f34a2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 17.3.12-tuxcare.18 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:201064d0-a259-5e0a-afde-be6766d1ce2c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 17.3.12-tuxcare.18 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:680a90f6-b87c-5193-b9b6-c8f5e53dc19a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 17.3.12-tuxcare.18 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:c2989405-ee3f-5031-a3a4-dba1b1fad6d0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 17.3.12-tuxcare.18 of @angular/router."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.18"
    }
  ]
}