{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:edab572d-a23a-5118-b57b-c822fa6a71d9",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/platform-webworker-dynamic",
      "purl": "pkg:npm/%40angular/platform-webworker-dynamic@7.2.16-tuxcare.10",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/platform-webworker-dynamic@7.2.16-tuxcare.10",
      "version": "7.2.16-tuxcare.10",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@7.2.16-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:d685e861-6ed1-59be-b314-93ce19e35823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 7.2.16-tuxcare.10 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@7.2.16-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:ca70eb79-56cf-56da-911b-e44192dddc29",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 7.2.16-tuxcare.10 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@7.2.16-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:c99ff1bf-2664-5f76-8aee-19acf660581d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 7.2.16-tuxcare.10 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@7.2.16-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:d51b9e47-cef1-56e8-8528-c6b07fe289cc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 7.2.16-tuxcare.10 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@7.2.16-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:7b8f3c98-8963-5d6b-9563-912f6fdbb4cf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 7.2.16-tuxcare.10 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@7.2.16-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:2f539ff3-d263-5e48-80e7-73305e3cd40b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 7.2.16-tuxcare.10 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@7.2.16-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:f839584a-df9c-5d71-a0c1-704ac8ee0e92",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 7.2.16-tuxcare.10 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@7.2.16-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:dd38f89b-0b93-5290-bc37-55584c4ccb9a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 7.2.16-tuxcare.10 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@7.2.16-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:01940028-a036-5dd8-bf7b-0aa1c142831c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 7.2.16-tuxcare.10 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@7.2.16-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:38cfda6a-9d52-54e0-b6e2-d92e252cece1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 7.2.16-tuxcare.10 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@7.2.16-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:6af60e7b-8324-59f7-9405-c7b2e4ab85d3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 7.2.16-tuxcare.10 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@7.2.16-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:b93998c6-b187-5996-8b74-3d4ee1fb52a3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 7.2.16-tuxcare.10 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@7.2.16-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:816a2bd9-b4cb-5e81-aa4c-594eb119987f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 7.2.16-tuxcare.10 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@7.2.16-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:be5ca8f3-a753-5989-b566-747caf3bb9b7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 7.2.16-tuxcare.10 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@7.2.16-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:2bb449fb-17ca-5cdc-b0ee-3ae36c37fd72",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 7.2.16-tuxcare.10 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@7.2.16-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:787f9ac8-428e-5f96-80c0-f86c38ed79d4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 7.2.16-tuxcare.10 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@7.2.16-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:ff572999-4d10-5ed3-8edd-2f9b7c52e52a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 7.2.16-tuxcare.10 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@7.2.16-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:4e9dee6c-57b9-5742-93e5-728beeae1737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 7.2.16-tuxcare.10 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@7.2.16-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:35080ca2-ae75-5c7e-bf2d-b630c7994045",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 7.2.16-tuxcare.10 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@7.2.16-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:c8a35108-fe0d-5950-ad84-52afa00b5fcf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 7.2.16-tuxcare.10 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@7.2.16-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:d02ff6bd-6e42-578a-b5b7-74eb27732652",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 7.2.16-tuxcare.10 of @angular/platform-webworker-dynamic. not_affected \u2014 Angular 7.2.16 is not affected by CVE-2026-68945. The vulnerability concerns HttpTransferCache's cache key generation logic that treats repeated HTTP parameters (`?role=user&role=admin`) and comma-separated values (`?role=user,admin`) as identical, causing cache key collisions. However, the HttpTransferCache feature does not exist in version 7.2.16\u2014it was introduced in Angular v16. While v7.2.1...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@7.2.16-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:63a9ea47-4c2d-514a-9718-3b2ac5ffc11e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 7.2.16-tuxcare.10 of @angular/platform-webworker-dynamic, and is fixed in 7.2.16-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@7.2.16-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:7d0fa6df-63d5-57f8-8eba-0f4d4498967d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 7.2.16-tuxcare.10 of @angular/platform-webworker-dynamic, and is fixed in 7.2.16-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@7.2.16-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:bd264f3e-8e28-5bce-851e-7093855f0bbc",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 7.2.16-tuxcare.10 of @angular/platform-webworker-dynamic. not_affected \u2014 Angular 7.2.16 is not affected by CVE-2026-88056. The vulnerability requires a String.prototype.trim() call on URLs during server-side rendering that strips Unicode whitespace characters, converting same-origin relative URLs into cross-origin protocol-relative URLs. This vulnerable code pattern does not exist in Angular 7.2.16. The CVE describes a vulnerability introduced in later Angular versi...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@7.2.16-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:3c6d61f0-3977-5192-8df9-aedf93d59648",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88057 does not affect version 7.2.16-tuxcare.10 of @angular/platform-webworker-dynamic. not_affected \u2014 Angular 7.2.16 is not affected by CVE-2026-88057. The vulnerability exists in the Ivy compiler's template pipeline (introduced in Angular 9+), which does not exist in this version. Angular 7.2.16 uses View Engine, where the SecurityContext determination for directive host bindings correctly uses the concrete host element name (`element.name`) rather than the directive's selector. The exploitati...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@7.2.16-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:ddd9e765-ea30-5daf-a21f-ff204dfa526f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 7.2.16-tuxcare.10 of @angular/platform-webworker-dynamic. not_affected \u2014 Angular 7.2.16 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, withRequestsMadeViaParent(), and client hydration features that were introduced in Angular v16+. Angular 7.2.16 predates these features by approximately 7 major versions. The codebase contains only legacy TransferState (manual key-value store) and NgModule-based HttpClient (no hierarchical delegation...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@7.2.16-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:9af8958f-794e-5875-ba65-03ca5ff37eec",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 7.2.16-tuxcare.10 of @angular/platform-webworker-dynamic."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-webworker-dynamic@7.2.16-tuxcare.10"
    }
  ]
}