{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:390d4266-4ecb-59df-956a-d8eb3836ec60",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/service-worker",
      "purl": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5",
      "version": "7.2.0-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:563e97b9-a4be-5f80-8896-a45589cdd558",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 7.2.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:fb0d264d-b00d-5e8d-a7fa-cd662521d093",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 7.2.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2922a6dc-967a-58dc-a9e4-c30b2ca1fe3e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 7.2.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:81a45e36-5891-5a45-8b96-b1a7cfd38b1c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 7.2.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8e1eddc8-3113-55b3-84a3-137d4db70367",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 7.2.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9fa6e00d-13d5-578e-af08-5bf3ac1e846c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 7.2.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:13f4f6f0-c9a1-5d9c-b22f-04c14c4e06f6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 7.2.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:87921eb3-dc52-5c36-9b99-5e265bbc24df",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 7.2.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7f6f1f8c-4d4d-5fcc-8504-34c675ec1df1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 7.2.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a5a5a904-37d2-56e7-b3b8-54ab21e6fad8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 7.2.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4193c87d-098e-5d07-9fe0-e0ded8f7de5d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 7.2.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a9bdb1c0-4d16-5b2d-b0bb-4fe211d2a0ac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 7.2.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1af0af66-509c-5465-8e21-c91ca33409d7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 7.2.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:bf1bde19-2ab1-5fd1-a107-ac3f5aabb81d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 7.2.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e60c8746-0887-5291-b42c-9f787850f5fc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 7.2.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7439f6c9-e87e-5f8f-bdbf-d2b5020751be",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 7.2.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8cef82ea-b749-5152-8b04-b8eafafcafd4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 7.2.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0ba2d56f-3f3f-5f9b-8388-3b27997b5300",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 7.2.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ba7b5788-f517-51c4-95c7-41a18dddc78c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 7.2.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:603fd3a5-7ab3-5c8f-bc83-3c260cedd803",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 7.2.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7c68db57-813f-5d8d-8c39-7a8e49664612",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 7.2.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2835f1d7-8c5a-5851-beef-e33b324fc0fe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 7.2.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8721a4d7-0d68-542c-8176-3d5b804b3988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 7.2.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:dc28f338-1d55-5af0-8bc1-59889ea1b3c6",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 7.2.0-tuxcare.5 of @angular/service-worker. not_affected \u2014 Angular v7.2.0 is NOT AFFECTED by CVE-2026-68945. The vulnerable component (HttpTransferCache) does not exist in this version. According to patch documentation in the repository (CVE-2026-50170.patch, CVE-2026-54266.patch), the HTTP transfer-cache and client hydration features were introduced in Angular v16. Angular v7.2.0 predates this feature by many major versions. Exhaustive searches confir...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8432b675-43d1-5132-8683-49d71a6bd5ca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 7.2.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:44879c81-040a-582c-b3b4-b7f1bdc76f3d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 7.2.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0a6fc01e-909f-53c3-9741-d5e4ec91ad94",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 7.2.0-tuxcare.5 of @angular/service-worker. not_affected \u2014 Angular version 7.2.0 is not affected by CVE-2026-88056. The vulnerability requires the presence of a `parseUrl` function in `packages/platform-server/src/url.ts` that uses `String.prototype.trim()` to normalize URLs, which strips Unicode whitespace and can convert validated same-origin relative URLs into cross-origin protocol-relative URLs. Version 7.2.0 does not contain the `url.ts` file; it ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:53228c27-2350-5d68-8c3c-01f254bcd433",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 7.2.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:84ab64d3-ef51-51e5-b8af-44cb960b89e5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 7.2.0-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6d6c23e1-04c0-5fd9-a72c-8b5c654f8959",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 7.2.0-tuxcare.5 of @angular/service-worker. not_affected \u2014 Angular v7.2.0 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache, hierarchical HttpClient delegation (withRequestsMadeViaParent()), and automatic HTTP response caching features that were introduced in Angular v16+. Version 7.2.0 uses NgModule-based configuration (HttpClientModule) with manual TransferState only\u2014no automatic HTTP-to-TransferState caching exists. The...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1ba31ee5-42f4-51b9-bd75-3b2441dbe36f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 7.2.0-tuxcare.5 of @angular/service-worker."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/service-worker@7.2.0-tuxcare.5"
    }
  ]
}