{
  "@id": "urn:uuid:78705251-8bf5-4728-9a4a-a804a030b407",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 2,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-10-03T17:45:00.393061+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:43:00.618933+00:00",
      "status_notes": "Vulnerability CVE-2021-4231 is fixed in version 7.2.11-tuxcare.6 of @angular/core.",
      "vulnerability": {
        "name": "CVE-2021-4231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:43:00.618933+00:00",
      "status_notes": "Vulnerability CVE-2025-66035 is fixed in version 7.2.11-tuxcare.6 of @angular/core.",
      "vulnerability": {
        "name": "CVE-2025-66035"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:43:00.618933+00:00",
      "status_notes": "Vulnerability CVE-2025-66412 is fixed in version 7.2.11-tuxcare.6 of @angular/core.",
      "vulnerability": {
        "name": "CVE-2025-66412"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:45:00.393061+00:00",
      "status_notes": "Vulnerability CVE-2026-101895 is fixed in version 7.2.11-tuxcare.6 of @angular/core.",
      "vulnerability": {
        "name": "CVE-2026-101895"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:43:00.618933+00:00",
      "status_notes": "Vulnerability CVE-2026-101896 affects version 7.2.11-tuxcare.6 of @angular/core.",
      "vulnerability": {
        "name": "CVE-2026-101896"
      },
      "action_statement": "Vulnerability CVE-2026-101896 affects version 7.2.11-tuxcare.6 of @angular/core."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:43:00.618933+00:00",
      "status_notes": "Vulnerability CVE-2026-22610 is fixed in version 7.2.11-tuxcare.6 of @angular/core.",
      "vulnerability": {
        "name": "CVE-2026-22610"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:43:00.618933+00:00",
      "status_notes": "Vulnerability CVE-2026-27970 is fixed in version 7.2.11-tuxcare.6 of @angular/core.",
      "vulnerability": {
        "name": "CVE-2026-27970"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:43:00.618933+00:00",
      "status_notes": "Vulnerability CVE-2026-41423 is fixed in version 7.2.11-tuxcare.6 of @angular/core.",
      "vulnerability": {
        "name": "CVE-2026-41423"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:43:00.618933+00:00",
      "status_notes": "Vulnerability CVE-2026-46417 is fixed in version 7.2.11-tuxcare.6 of @angular/core.",
      "vulnerability": {
        "name": "CVE-2026-46417"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:43:00.618933+00:00",
      "status_notes": "Vulnerability CVE-2026-50168 does not affect version 7.2.11-tuxcare.6 of @angular/core. not_affected \u2014 CVE-2026-50168 addresses vulnerabilities in the WHATWG URL-based parseUrl implementation and allowedHosts validation feature introduced in Angular's CVE-2026-41423 fix. The target (v7.2.11) uses a completely different architecture with Node.js legacy url.parse() and does not have the allowedHosts feature. The specific vulnerable code patterns that CVE-2026-50168 patches do not exist in this ver...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-50168"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-50168 addresses vulnerabilities in the WHATWG URL-based parseUrl implementation and allowedHosts validation feature introduced in Angular's CVE-2026-41423 fix. The target (v7.2.11) uses a completely different architecture with Node.js legacy url.parse() and does not have the allowedHosts feature. The specific vulnerable code patterns that CVE-2026-50168 patches do not exist in this ver..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:43:00.618933+00:00",
      "status_notes": "Vulnerability CVE-2026-50169 is fixed in version 7.2.11-tuxcare.6 of @angular/core.",
      "vulnerability": {
        "name": "CVE-2026-50169"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:43:00.618933+00:00",
      "status_notes": "Vulnerability CVE-2026-50170 does not affect version 7.2.11-tuxcare.6 of @angular/core. not_affected \u2014 Angular v7.2.11 is not affected by CVE-2026-50170. The HTTP Transfer Cache feature that is vulnerable does not exist in this version. The feature was introduced in Angular v16+, and v7.2.11 lacks the transfer_cache.ts module, withHttpTransferCache provider, and provideClientHydration functionality entirely.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-50170"
      },
      "impact_statement": "not_affected \u2014 Angular v7.2.11 is not affected by CVE-2026-50170. The HTTP Transfer Cache feature that is vulnerable does not exist in this version. The feature was introduced in Angular v16+, and v7.2.11 lacks the transfer_cache.ts module, withHttpTransferCache provider, and provideClientHydration functionality entirely."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:43:00.618933+00:00",
      "status_notes": "Vulnerability CVE-2026-50171 is fixed in version 7.2.11-tuxcare.6 of @angular/core.",
      "vulnerability": {
        "name": "CVE-2026-50171"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:43:00.618933+00:00",
      "status_notes": "Vulnerability CVE-2026-50184 is fixed in version 7.2.11-tuxcare.6 of @angular/core.",
      "vulnerability": {
        "name": "CVE-2026-50184"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:43:00.618933+00:00",
      "status_notes": "Vulnerability CVE-2026-50555 is fixed in version 7.2.11-tuxcare.6 of @angular/core.",
      "vulnerability": {
        "name": "CVE-2026-50555"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:43:00.618933+00:00",
      "status_notes": "Vulnerability CVE-2026-50556 is fixed in version 7.2.11-tuxcare.6 of @angular/core.",
      "vulnerability": {
        "name": "CVE-2026-50556"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:43:00.618933+00:00",
      "status_notes": "Vulnerability CVE-2026-50557 is fixed in version 7.2.11-tuxcare.6 of @angular/core.",
      "vulnerability": {
        "name": "CVE-2026-50557"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:43:00.618933+00:00",
      "status_notes": "Vulnerability CVE-2026-52725 is fixed in version 7.2.11-tuxcare.6 of @angular/core.",
      "vulnerability": {
        "name": "CVE-2026-52725"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:43:00.618933+00:00",
      "status_notes": "Vulnerability CVE-2026-54264 does not affect version 7.2.11-tuxcare.6 of @angular/core. not_affected \u2014 Angular 7.2.11-tuxcare.2 is not affected by CVE-2026-54264. The vulnerability concerns sensitive header leakage on cross-origin redirects in the request metadata preservation feature. This version predates that feature entirely - it strips ALL request headers when making network requests for assets, as evidenced by code comments and the absence of the newRequestWithMetadata method introduced in...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54264"
      },
      "impact_statement": "not_affected \u2014 Angular 7.2.11-tuxcare.2 is not affected by CVE-2026-54264. The vulnerability concerns sensitive header leakage on cross-origin redirects in the request metadata preservation feature. This version predates that feature entirely - it strips ALL request headers when making network requests for assets, as evidenced by code comments and the absence of the newRequestWithMetadata method introduced in..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:43:00.618933+00:00",
      "status_notes": "Vulnerability CVE-2026-54265 does not affect version 7.2.11-tuxcare.6 of @angular/core. not_affected \u2014 Angular 7.2.11-tuxcare.2 uses View Engine compiler architecture, not Ivy. The vulnerability (CVE-2026-54265) is specific to Ivy's template compiler pipeline where TwoWayProperty operations were missing from the sanitizer resolution switch. View Engine does not have TwoWayProperty operations; two-way bindings desugar early in the template parser to the same parsePropertyBinding() code path as on...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54265"
      },
      "impact_statement": "not_affected \u2014 Angular 7.2.11-tuxcare.2 uses View Engine compiler architecture, not Ivy. The vulnerability (CVE-2026-54265) is specific to Ivy's template compiler pipeline where TwoWayProperty operations were missing from the sanitizer resolution switch. View Engine does not have TwoWayProperty operations; two-way bindings desugar early in the template parser to the same parsePropertyBinding() code path as on..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:43:00.618933+00:00",
      "status_notes": "Vulnerability CVE-2026-54266 does not affect version 7.2.11-tuxcare.6 of @angular/core. not_affected \u2014 Angular 7.2.11-tuxcare.2 is not affected by CVE-2026-54266. The HttpTransferCache feature that contains the weak hash vulnerability does not exist in this version - it was introduced in Angular 16.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54266"
      },
      "impact_statement": "not_affected \u2014 Angular 7.2.11-tuxcare.2 is not affected by CVE-2026-54266. The HttpTransferCache feature that contains the weak hash vulnerability does not exist in this version - it was introduced in Angular 16."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:43:00.618933+00:00",
      "status_notes": "Vulnerability CVE-2026-54267 is fixed in version 7.2.11-tuxcare.6 of @angular/core.",
      "vulnerability": {
        "name": "CVE-2026-54267"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:43:00.618933+00:00",
      "status_notes": "Vulnerability CVE-2026-54268 is fixed in version 7.2.11-tuxcare.6 of @angular/core.",
      "vulnerability": {
        "name": "CVE-2026-54268"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:43:00.618933+00:00",
      "status_notes": "Vulnerability CVE-2026-68945 does not affect version 7.2.11-tuxcare.6 of @angular/core. not_affected \u2014 Angular v7.2.11-tuxcare.3 is NOT AFFECTED by CVE-2026-68945. The vulnerability affects Angular's `HttpTransferCache` feature, which caches HTTP requests during Server-Side Rendering (SSR) for client-side hydration. This feature did not exist in v7.2.11 \u2014 it was introduced in Angular v16. The vulnerable file `packages/common/http/src/transfer_cache.ts` is absent from the target SHA (8c4c3a453736...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-68945"
      },
      "impact_statement": "not_affected \u2014 Angular v7.2.11-tuxcare.3 is NOT AFFECTED by CVE-2026-68945. The vulnerability affects Angular's `HttpTransferCache` feature, which caches HTTP requests during Server-Side Rendering (SSR) for client-side hydration. This feature did not exist in v7.2.11 \u2014 it was introduced in Angular v16. The vulnerable file `packages/common/http/src/transfer_cache.ts` is absent from the target SHA (8c4c3a453736..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:43:00.618933+00:00",
      "status_notes": "Vulnerability CVE-2026-69149 is fixed in version 7.2.11-tuxcare.6 of @angular/core.",
      "vulnerability": {
        "name": "CVE-2026-69149"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:43:00.618933+00:00",
      "status_notes": "Vulnerability CVE-2026-69151 is fixed in version 7.2.11-tuxcare.6 of @angular/core.",
      "vulnerability": {
        "name": "CVE-2026-69151"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:43:00.618933+00:00",
      "status_notes": "Vulnerability CVE-2026-88056 does not affect version 7.2.11-tuxcare.6 of @angular/core. not_affected \u2014 Angular 7.2.11 is not affected by CVE-2026-88056. The vulnerability requires calling String.prototype.trim() on URL strings before WHATWG URL parsing, creating a discrepancy that enables SSRF. This vulnerable code pattern was introduced in Angular 14+ with a new url.ts file containing parseUrl() that called .trim(). Angular 7.2.11 uses a different parseUrl() implementation in location.ts that d...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-88056"
      },
      "impact_statement": "not_affected \u2014 Angular 7.2.11 is not affected by CVE-2026-88056. The vulnerability requires calling String.prototype.trim() on URL strings before WHATWG URL parsing, creating a discrepancy that enables SSRF. This vulnerable code pattern was introduced in Angular 14+ with a new url.ts file containing parseUrl() that called .trim(). Angular 7.2.11 uses a different parseUrl() implementation in location.ts that d..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:43:00.618933+00:00",
      "status_notes": "Vulnerability CVE-2026-88057 is fixed in version 7.2.11-tuxcare.6 of @angular/core.",
      "vulnerability": {
        "name": "CVE-2026-88057"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:43:00.618933+00:00",
      "status_notes": "Vulnerability CVE-2026-88058 is fixed in version 7.2.11-tuxcare.6 of @angular/core.",
      "vulnerability": {
        "name": "CVE-2026-88058"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:43:00.618933+00:00",
      "status_notes": "Vulnerability CVE-2026-88059 does not affect version 7.2.11-tuxcare.6 of @angular/core. not_affected \u2014 Angular 7.2.11 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache interceptor and hierarchical HttpClient configuration APIs (withRequestsMadeViaParent, provideHttpClient) that were introduced in Angular 14+ and do not exist in this version. While TransferState exists in 7.2.11 as a basic SSR state transfer mechanism, there is no automatic HTTP response caching to T...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-88059"
      },
      "impact_statement": "not_affected \u2014 Angular 7.2.11 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache interceptor and hierarchical HttpClient configuration APIs (withRequestsMadeViaParent, provideHttpClient) that were introduced in Angular 14+ and do not exist in this version. While TransferState exists in 7.2.11 as a basic SSR state transfer mechanism, there is no automatic HTTP response caching to T..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/core@7.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/core@7.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T17:43:00.618933+00:00",
      "status_notes": "Vulnerability CVE-2026-88060 is fixed in version 7.2.11-tuxcare.6 of @angular/core.",
      "vulnerability": {
        "name": "CVE-2026-88060"
      }
    }
  ]
}
