{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b730012a-e898-5dfc-a3b7-523c23e0afb2",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/router",
      "purl": "pkg:npm/%40angular/router@18.2.14-tuxcare.14",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.14",
      "version": "18.2.14-tuxcare.14",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:83e66077-b0d4-5436-b123-c002e517538d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.14-tuxcare.14 of @angular/router."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:1919ff55-d754-5cbd-9c42-93a7d6ce2a13",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.2.14-tuxcare.14 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:21edb5c8-761f-50a9-9e69-6d2f6cef6798",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.2.14-tuxcare.14 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:2c026e56-4e2f-5eab-8ce7-385710b7ef11",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.2.14-tuxcare.14 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:fc70be5e-45c6-5902-82fc-795022743bc8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.2.14-tuxcare.14 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:90bb899f-b86e-5d3b-b788-60de30c739db",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 18.2.14-tuxcare.14 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:f85aece4-a8bf-587b-b8e9-119176dcca2a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 18.2.14-tuxcare.14 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:222f4340-fa3a-5e14-848b-e0c439eeb43b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 18.2.14-tuxcare.14 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:3dea5cc7-dfb1-5c07-b48e-bbff7d6cc88f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 18.2.14-tuxcare.14 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:833f301e-e094-5862-856c-2ef0cd570711",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 18.2.14-tuxcare.14 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:f549af23-50cf-5910-a181-f2a738ea76e4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 18.2.14-tuxcare.14 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:5bb18f0d-42ab-5310-af84-d960235a6d20",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 18.2.14-tuxcare.14 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:b61dfb6a-8664-5ce0-b14d-271c2784b55f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 18.2.14-tuxcare.14 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:412bf44a-15c4-5f5c-9166-cebc984742e8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 18.2.14-tuxcare.14 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:1eabd2b8-fd2a-5381-8938-bd66938534c5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 18.2.14-tuxcare.14 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:40596894-b70c-5390-b9cf-e1d59b461c08",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 18.2.14-tuxcare.14 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:0aadcf34-67de-5d95-8568-0992fa1da075",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 18.2.14-tuxcare.14 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:301f837d-4082-56f8-bf2e-c6a316f4cdec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 18.2.14-tuxcare.14 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:edd01f79-75d8-55e5-b431-4654556600da",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 18.2.14-tuxcare.14 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:3fafe520-2891-5807-b2a8-9e621af0f8b3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 18.2.14-tuxcare.14 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:6c79daef-4516-5ba1-bec6-22486351e743",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 18.2.14-tuxcare.14 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:b3d246db-a50d-5e5d-8017-9f82fe6355d9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 18.2.14-tuxcare.14 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:b6541664-8cb4-5495-837c-a392655e85ac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 18.2.14-tuxcare.14 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:59e27ce8-ad9b-563c-beba-61d461160de5",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.2.14-tuxcare.14 of @angular/router. not_affected \u2014 The target version 18.2.14-tuxcare.13 is NOT affected by CVE-2026-88056. The vulnerable code pattern (calling String.prototype.trim() on URL strings before resolution) was never present in this version. The target uses a refactored parseUrl() implementation introduced via commit 49a60f6045 (May 2026) that correctly handles Unicode whitespace by percent-encoding it rather than stripping it, main...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:65160031-6bc1-535e-aab4-2fe97564316a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 18.2.14-tuxcare.14 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:009f033e-8d33-5345-ab72-5d83c377c43d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 18.2.14-tuxcare.14 of @angular/router."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:a3b742ac-865f-5337-bf13-80b523be3b5b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 18.2.14-tuxcare.14 of @angular/router."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/router@18.2.14-tuxcare.14"
    }
  ]
}