{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:66e555ad-057e-5e6e-8e57-bb43ace18043",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/router",
      "purl": "pkg:npm/%40angular/router@17.3.12-tuxcare.6",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.6",
      "version": "17.3.12-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9afd71e3-3cb9-574c-b625-f4feeee28cb4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.3.12-tuxcare.6 of @angular/router."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5dc89636-d333-5826-bb17-ec32890121a1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.3.12-tuxcare.6 of @angular/router."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:07f76841-fefe-55d8-b5a8-e44352d7a128",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.3.12-tuxcare.6 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e795a746-50a6-548b-a734-737b273926c9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.3.12-tuxcare.6 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9d7bc312-2240-59be-85f7-c2887f7036f0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 17.3.12-tuxcare.6 of @angular/router, and is fixed in 17.3.12-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:30fdcd94-6a23-53a6-8ba4-618cefcc1462",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32635 affects version 17.3.12-tuxcare.6 of @angular/router, and is fixed in 17.3.12-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:023c92b0-4d4c-5d12-b476-3b0f10393557",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 17.3.12-tuxcare.6 of @angular/router, and is fixed in 17.3.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ca381888-35c5-5b1c-87f9-f2eaf4fb5502",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 17.3.12-tuxcare.6 of @angular/router, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b5b021fb-069c-58b5-a221-6f595c5cba72",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 17.3.12-tuxcare.6 of @angular/router, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3ddea468-6288-58b7-a717-e3fa092f4149",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 17.3.12-tuxcare.6 of @angular/router, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:56d68848-40f2-5f1b-bf0e-7d432ad28bab",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 17.3.12-tuxcare.6 of @angular/router, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2168a470-a273-5dd7-9c9b-c90afc02c40b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 17.3.12-tuxcare.6 of @angular/router, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f1afa890-0769-5d95-bc51-64edc9cc9c62",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 17.3.12-tuxcare.6 of @angular/router, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c60e1456-de5a-57c8-86fe-306e6c16e7cc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 17.3.12-tuxcare.6 of @angular/router, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8d7ef9c6-fa72-5c41-804a-40b2a7a49695",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 17.3.12-tuxcare.6 of @angular/router, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:035d3efa-1066-547a-9597-107b9381a58b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 17.3.12-tuxcare.6 of @angular/router, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:33efbca4-2ce2-5204-9bee-f7dbca6031d1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 17.3.12-tuxcare.6 of @angular/router, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4e47b044-9bae-525b-85a3-88862ee012e1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 17.3.12-tuxcare.6 of @angular/router, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a904cdd9-a57d-5e77-8ab1-d408b205fc2d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 17.3.12-tuxcare.6 of @angular/router, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4c178803-52ae-528a-bbfd-1471349b3d3e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 17.3.12-tuxcare.6 of @angular/router, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2d1ca279-db4d-5688-9427-b633baef8516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 17.3.12-tuxcare.6 of @angular/router, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d691cffa-749c-5ee0-8f03-d262fe2ab160",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 17.3.12-tuxcare.6 of @angular/router, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d6dbb261-3c80-5b6b-a069-89edd3caf5a7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 17.3.12-tuxcare.6 of @angular/router, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a368fc0a-227f-5072-8b99-9a7493061704",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 17.3.12-tuxcare.6 of @angular/router, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:86d2e322-b3b4-5602-bba2-40e378224e71",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.3.12-tuxcare.6 of @angular/router. not_affected \u2014 Version 17.3.12 is not affected by CVE-2026-88056. The vulnerability involves String.prototype.trim() being applied during URL resolution in Angular's platform-server, converting validated same-origin URLs with Unicode whitespace into cross-origin protocol-relative URLs, leading to SSRF. This vulnerable code pattern was introduced in newer Angular versions (v20+) and does not exist in version 1...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:898fefba-7b8c-5b55-bd3d-81a3e21035f8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 17.3.12-tuxcare.6 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:12dc50e0-c612-51fa-997a-39c2c60d9e05",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 17.3.12-tuxcare.6 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:603dcaf2-8bb6-508d-89e9-d3bbce408504",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 17.3.12-tuxcare.6 of @angular/router."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/router@17.3.12-tuxcare.6"
    }
  ]
}