{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1a0b0d8a-731f-59b3-af72-1ee1281a567c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/router@5.2.7-tuxcare.5",
      "type": "library",
      "name": "@angular/router",
      "version": "5.2.7-tuxcare.5",
      "purl": "pkg:npm/%40angular/router@5.2.7-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:cfa4f2e7-ac4b-58a3-8a52-49368fd2612a",
      "id": "CVE-2021-4231",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.7-tuxcare.5 of @angular/router."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@5.2.7-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56ce13b0-08ea-599d-bf61-c71814ac4231",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 5.2.7-tuxcare.5 of @angular/router."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@5.2.7-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:103904f2-6f17-5417-bc05-361d2dd03a48",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.7-tuxcare.5 of @angular/router."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@5.2.7-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9f9fe3a-78b0-5ef5-a6d4-1239417103de",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.7-tuxcare.5 of @angular/router."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@5.2.7-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2601fa07-3e0e-5009-a5f3-bdf330a9c020",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.2.7-tuxcare.5 of @angular/router."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@5.2.7-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a6250c6-da5c-5fb6-b5d9-25a28ab11174",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41423 does not affect version 5.2.7-tuxcare.5 of @angular/router. not_affected \u2014 Angular version 5.2.7 is not affected by CVE-2026-41423. The vulnerability exists in later Angular versions (9+) that use the WHATWG URL API with hostname tracking. Version 5.2.7 uses Node's legacy url.parse() API and only tracks pathname/search/hash components, making the SSRF attack vector via hostname override impossible."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@5.2.7-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28276530-92df-5dc2-9450-bc7a48643a75",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 5.2.7-tuxcare.5 of @angular/router."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@5.2.7-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d570cc9-fcce-5f0f-b478-97eb092c6570",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 5.2.7-tuxcare.5 of @angular/router."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@5.2.7-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef411f38-8ab1-5f1c-8ceb-fb3e837c369f",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 5.2.7-tuxcare.5 of @angular/router."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@5.2.7-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76dbd271-07ca-5241-8fa7-eb444eda34f4",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50170 does not affect version 5.2.7-tuxcare.5 of @angular/router. not_affected \u2014 Angular 5.2.7 is not affected by CVE-2026-50170. The HTTP transfer cache feature that contains the vulnerability does not exist in this version. The transfer cache mechanism was introduced in Angular v16+, and Angular 5.2.7 predates this feature by many major versions."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@5.2.7-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b8654f1-e390-5169-97d8-e4683d846c79",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 5.2.7-tuxcare.5 of @angular/router."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@5.2.7-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c327ba1-e028-571d-b44b-a6fc4753c4e0",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 5.2.7-tuxcare.5 of @angular/router."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@5.2.7-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:665c9677-990f-5b1a-b3cc-54d23b9818b0",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 5.2.7-tuxcare.5 of @angular/router."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@5.2.7-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92db9538-b2d4-5537-9a1e-ff54b67a760e",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 5.2.7-tuxcare.5 of @angular/router."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@5.2.7-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:033ac501-a47a-5b6b-b673-b25b9a29f149",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 5.2.7-tuxcare.5 of @angular/router."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@5.2.7-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:117517f3-a9a5-5589-b2cf-b1f3ec9e39e0",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 5.2.7-tuxcare.5 of @angular/router."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@5.2.7-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d72d866-5446-5e7d-a6e5-46e817da890d",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54264 does not affect version 5.2.7-tuxcare.5 of @angular/router. not_affected \u2014 Angular v5.2.7 is NOT affected by CVE-2026-54264. The service worker's asset-group request reconstruction uses URL-only rebuilding via adapter.newRequest(req.url), which creates fresh Request objects with no headers from the original request. Since headers are never forwarded in the first place, there is no opportunity for sensitive headers to leak on cross-origin redirects. The vulnerable code..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@5.2.7-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:281488ab-ac04-5e19-a516-e78de0bcb71b",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 5.2.7-tuxcare.5 of @angular/router. not_affected \u2014 Angular 5.2.7-tuxcare.2 uses the View Engine compiler architecture, which does not have the vulnerable TwoWayProperty operation present in Ivy. Two-way bindings desugar through the same parsePropertyBinding() code path as one-way bindings and receive identical schema-derived sanitization. The vulnerability requires the Ivy template compiler pipeline with resolve_sanitizers.ts missing the TwoWay..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@5.2.7-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf7ac19e-2697-5337-b7ab-331f365520d6",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54266 does not affect version 5.2.7-tuxcare.5 of @angular/router. not_affected \u2014 Angular 5.2.7 is NOT affected by CVE-2026-54266. The vulnerable HttpTransferCache feature does not exist in this version (introduced in Angular v16+). No code path processes HTTP requests for automatic transfer cache key generation."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@5.2.7-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:badbb439-67b0-5512-9e4c-4f786c5f6b69",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 5.2.7-tuxcare.5 of @angular/router."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@5.2.7-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45b10225-2e8c-59a7-851b-7f6e9700952b",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 5.2.7-tuxcare.5 of @angular/router."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@5.2.7-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e979031-d4bd-5bb5-917b-598c9f5f40a0",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.7-tuxcare.5 of @angular/router. not_affected \u2014 Angular 5.2.7 is not affected by CVE-2026-68945. The vulnerable component HttpTransferCache does not exist in this version\u2014it was introduced in Angular v16. Angular 5.2.7 has only a generic TransferState key-value store with no automatic HTTP request caching or cache-key generation from HttpParams. The CVE-described vulnerability (cache-key collision when repeated parameter values are joined wi..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@5.2.7-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21a9e8c6-59e8-52ae-824c-58951a5e7bc9",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 5.2.7-tuxcare.5 of @angular/router."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@5.2.7-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d83d3cfe-fa8f-5b13-bf0c-751f3607a8a4",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 5.2.7-tuxcare.5 of @angular/router."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@5.2.7-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ace5c7ee-3f99-5b3d-96d7-ba6bfe2fb541",
      "id": "CVE-2026-88056",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.7-tuxcare.5 of @angular/router. not_affected \u2014 CVE-2026-88056 describes a Unicode whitespace bypass vulnerability in Angular's SSR URL resolution utility (packages/platform-server/src/url.ts parseUrl function that uses String.prototype.trim()). This vulnerable component does not exist in version 5.2.7-tuxcare.5. The url.ts module was introduced in later commits (e46f82d67e on 2026-06-25, after the current HEAD dated 2026-08-14 but on a diff..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@5.2.7-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4110257-4f45-5748-b089-eaca59727e46",
      "id": "CVE-2026-88057",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88057 does not affect version 5.2.7-tuxcare.5 of @angular/router. not_affected \u2014 Angular 5.2.7 is not affected by CVE-2026-88057. The vulnerability pattern described in the CVE (compiler using directive selector instead of concrete host element for SecurityContext determination in host bindings) does not exist in this version. Angular 5.2.7 correctly uses the element name when determining SecurityContext for directive host bindings, as evidenced in template_parser.ts and bi..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@5.2.7-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7cd2f6c-dadd-5692-bcdd-08bcb91ca7e5",
      "id": "CVE-2026-88059",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.7-tuxcare.5 of @angular/router. not_affected \u2014 Angular v5.2.7 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache (an HTTP interceptor that automatically caches responses into TransferState during SSR) and hierarchical HttpClient configuration with withRequestsMadeViaParent(). These features were introduced in Angular v16+; they do not exist in v5.2.7. While v5 has both HttpClient (input receiver) and TransferSta..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@5.2.7-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6df8e58-a3ba-521f-8353-32fa386132ba",
      "id": "CVE-2026-88060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 5.2.7-tuxcare.5 of @angular/router."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/router@5.2.7-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/router@5.2.7-tuxcare.5"
    }
  ]
}