{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8ca277b0-d16a-5014-9b33-654b880474e6",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/router",
      "purl": "pkg:npm/%40angular/router@17.1.0-tuxcare.5",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5",
      "version": "17.1.0-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:06f87818-2cff-5d44-bfd5-9541df210333",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.1.0-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:379e95e0-b450-53ac-bd4c-3fda60ec9b41",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.1.0-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9979fb0f-5e8f-5249-82d2-22c49aed267f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.1.0-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6732ed84-1cbc-5cfc-8ef7-7b8eeb206824",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.1.0-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9bd8fd2d-e5d2-5602-84fc-79dc5021726c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.1.0-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4fa78fe8-070c-50fd-a019-b2fe5c7191b9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.1.0-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2b23624d-75b5-5bcf-923b-ed4551f1944c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 17.1.0-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:546020c4-0d4f-5fe8-b7c5-545d11b5fd8b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.1.0-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:485fab44-6a0e-5626-a3d5-60748c6571e6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.1.0-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e0409f23-9944-5901-8c22-c4f0985c6635",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.1.0-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:040b7f3b-089b-5cd1-9a11-112f75678e6b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.1.0-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:aa79729d-adfa-525b-a8d0-fc83ddd62ccf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.1.0-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f61f02a5-f82b-5e7c-9ff9-448f9e476b11",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.1.0-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:75c4c943-d4ae-5e69-9b66-33f998ea1a13",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.1.0-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:820a94f8-4c22-5cd9-9796-ed06f99824c6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.1.0-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:aa568228-3b9c-5bed-ad35-77236c82c61c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.1.0-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1ffaf309-56a3-5220-8c9c-f1bbd3a7ff65",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.1.0-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9f789ea0-4310-5cf0-b50d-13fbea5352a8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.1.0-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e90953c4-2f42-5c32-9914-78793c4b1deb",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 17.1.0-tuxcare.5 of @angular/router. not_affected \u2014 Angular v17.1.0 does not have the TwoWayProperty IR operation that is the subject of CVE-2026-54265. Two-way bindings are desugared into separate property and event bindings before template pipeline processing, with the property half using the same parsePropertyBinding() code path as one-way property bindings, which are properly sanitized.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:778500b6-6557-5076-a20d-7e79816be240",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.1.0-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5ba74fa3-6c0f-5d0e-92b4-76ddd8c19d63",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.1.0-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9f0bf6a6-2efc-5ea5-988e-5c477ddf757a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.1.0-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9607ea75-042b-5672-b795-3becab692c82",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 17.1.0-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d20b5a1d-ea36-5b74-a243-e8a0e467a379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 17.1.0-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1b30ed68-db46-504e-a001-104f1181df80",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 17.1.0-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:77feb7d7-ce2d-536c-9ae9-1180ed3869c9",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.1.0-tuxcare.5 of @angular/router. not_affected \u2014 Angular 17.1.0 was never vulnerable to CVE-2026-88056. The vulnerability exists only in newer Angular versions (v18+, v19+, v20+ before fixes) where a url.ts file with a parseUrl function that uses String.prototype.trim() was introduced. Angular 17.1.0 does not have this file in the upstream release. TuxCare created url.ts for their 17.1.0 fork (commit e06d36f339 by ejarocki@cloudlinux.com) but...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:27946b0a-ab17-51b8-89b0-efbbf2ac3075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 17.1.0-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b754d88b-98cb-5a97-9f75-5a2b857e9975",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 17.1.0-tuxcare.5 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2caf6383-f756-51f7-9503-65b46d26b326",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 17.1.0-tuxcare.5 of @angular/router."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/router@17.1.0-tuxcare.5"
    }
  ]
}