{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:68347341-12eb-516f-9f42-3b8f9d7c4ea7",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/router",
      "purl": "pkg:npm/%40angular/router@18.2.14-tuxcare.17",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17",
      "version": "18.2.14-tuxcare.17",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:bb24252b-87a1-595c-99ce-b73bb0cce3d2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.14-tuxcare.17 of @angular/router."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:968b8fc2-0106-53f4-a3c6-c47cc436bb10",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.2.14-tuxcare.17 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:58a2a8b7-e7fb-5da7-ac85-8228a08debe7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 18.2.14-tuxcare.17 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:bf34f951-39fd-506e-b4e8-d64d550bf8fd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 18.2.14-tuxcare.17 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:db541f5d-2e7e-5cb5-b622-e9d17ee68ad6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.2.14-tuxcare.17 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:c0c73be2-ed2a-5afb-8b32-9437b773e2f5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.2.14-tuxcare.17 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:9c6fd11e-479b-591c-8335-81a1b4228919",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.2.14-tuxcare.17 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:40ff238d-31f9-5ddd-9037-6d5c9ee0b85e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 18.2.14-tuxcare.17 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:b733ac47-2db3-5957-81da-8a0391fc88bf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 18.2.14-tuxcare.17 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:18de8a22-f261-5ef4-b3b8-8ec04b9d83f3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 18.2.14-tuxcare.17 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:82dc62c7-0254-56e6-a329-b079aeaf6455",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 18.2.14-tuxcare.17 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:7a671a65-5391-568d-bb7b-ae20fd0718cb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 18.2.14-tuxcare.17 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:d505242b-e95a-5e83-8b82-e31eb994ebfc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 18.2.14-tuxcare.17 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:411223e3-fdc5-59d6-8bbc-119a805db41c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 18.2.14-tuxcare.17 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:1d9d423b-665c-50f5-95b7-d912c4367cdc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 18.2.14-tuxcare.17 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:e7576f47-3d84-545a-87ca-643fb790b709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 18.2.14-tuxcare.17 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:ab4c518b-1fd8-56c5-858a-1b474eb1097f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 18.2.14-tuxcare.17 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:14660e55-8cc7-5fe3-8e17-a43ae9dc254f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 18.2.14-tuxcare.17 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:153d76ec-9e65-54da-bbbb-50841c75b720",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 18.2.14-tuxcare.17 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:273d1f7f-1f33-507d-88cc-42055dcda707",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 18.2.14-tuxcare.17 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:0928c17e-62a4-5c19-93a3-beff484d0665",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 18.2.14-tuxcare.17 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:ada445c2-704d-5915-9ed7-e296d43d39f0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 18.2.14-tuxcare.17 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:a6e9b75d-96e4-58dc-9ab5-7295a47388d1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 18.2.14-tuxcare.17 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:af10d16c-0dc2-55b8-ad1a-cb6866440a9a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 18.2.14-tuxcare.17 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:31a09f46-bd77-5de5-aaeb-dfda0d5d437d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 18.2.14-tuxcare.17 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:11d28c67-a542-5545-ab2c-e6e0b7b51271",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.2.14-tuxcare.17 of @angular/router. not_affected \u2014 The target version 18.2.14-tuxcare.13 is NOT affected by CVE-2026-88056. The vulnerable code pattern (calling String.prototype.trim() on URL strings before resolution) was never present in this version. The target uses a refactored parseUrl() implementation introduced via commit 49a60f6045 (May 2026) that correctly handles Unicode whitespace by percent-encoding it rather than stripping it, main...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:5a0f7b69-a04e-5f42-964f-641e58414b7d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 18.2.14-tuxcare.17 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:c96ef326-c159-5415-9b8c-64fd68e29c5a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 18.2.14-tuxcare.17 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:ffc73ba1-cac7-593f-898c-f8f40c42cd5e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 18.2.14-tuxcare.17 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:716cb1cb-31da-5289-9c64-452f3086c5b5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 18.2.14-tuxcare.17 of @angular/router."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.17"
    }
  ]
}