{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fbb532af-09d4-52c4-b87c-d39faaf6f1d2",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/elements",
      "purl": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3",
      "version": "7.2.0-tuxcare.3",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:a3c65d2a-4695-5abe-8799-ffa616db7500",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 7.2.0-tuxcare.3 of @angular/elements."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:28d05280-0190-5e4d-a7ce-ca07cc3ec022",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 7.2.0-tuxcare.3 of @angular/elements."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:dad74464-842d-52ab-94f6-9bd49ff989c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 7.2.0-tuxcare.3 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:9ac17a57-d43b-50bd-b9f6-5765fb83b892",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 7.2.0-tuxcare.3 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:03a93d16-a2e8-50aa-b393-8a425928da7e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 7.2.0-tuxcare.3 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:284fbe7f-062e-57ed-b8ab-1c6395f4181d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 7.2.0-tuxcare.3 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:0298b179-3eca-5285-8cf1-ec435ac1ae6e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 7.2.0-tuxcare.3 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:0504ac0b-0b7c-5bea-b52a-17bd3b0e250c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 7.2.0-tuxcare.3 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:bc54b83e-f94b-5c9f-92e5-868342e9c7f7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 7.2.0-tuxcare.3 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:06b9413f-b677-54e1-99f2-537d36932fab",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 7.2.0-tuxcare.3 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:072c7be6-7dd3-5f01-bc77-a86586544994",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 7.2.0-tuxcare.3 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:a7d84f86-4148-595a-a565-5a0091f4a13e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 7.2.0-tuxcare.3 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:109a3875-4867-5ba6-94bc-2ad69992bed2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 7.2.0-tuxcare.3 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:262b33f6-3332-50be-b191-9b7ef88d3654",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 7.2.0-tuxcare.3 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:a01e29dc-b3c6-5f60-b058-f5a37c7b6fd8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 7.2.0-tuxcare.3 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:21550f4f-a0b8-54b6-90d2-3fcc2d6e0383",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 7.2.0-tuxcare.3 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:fde2fd05-0290-5edf-b25c-ea963976bf2e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 7.2.0-tuxcare.3 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:938f2cb3-4da4-522c-b8ce-19de94c0ca7d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 7.2.0-tuxcare.3 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:0eb435b2-58dd-5f12-a3e6-dca160688f86",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 7.2.0-tuxcare.3 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:ca998921-5982-5c50-81b1-bac04368bf70",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 7.2.0-tuxcare.3 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:1456c7a5-074c-56aa-859a-08756532239c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 7.2.0-tuxcare.3 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:0a5b5a34-571e-553d-8050-e58758a269a7",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 7.2.0-tuxcare.3 of @angular/elements. not_affected \u2014 Angular v7.2.0 is NOT AFFECTED by CVE-2026-68945. The vulnerable component (HttpTransferCache) does not exist in this version. According to patch documentation in the repository (CVE-2026-50170.patch, CVE-2026-54266.patch), the HTTP transfer-cache and client hydration features were introduced in Angular v16. Angular v7.2.0 predates this feature by many major versions. Exhaustive searches confir...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:cb70f2bc-c0c9-5d5e-8d9c-e932c54c121d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 7.2.0-tuxcare.3 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:d508ce20-cc6b-5220-9130-82be0dcfb1a7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 7.2.0-tuxcare.3 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:a2e84218-25c6-5f37-9850-0ebda2e6d8a8",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 7.2.0-tuxcare.3 of @angular/elements. not_affected \u2014 Angular version 7.2.0 is not affected by CVE-2026-88056. The vulnerability requires the presence of a `parseUrl` function in `packages/platform-server/src/url.ts` that uses `String.prototype.trim()` to normalize URLs, which strips Unicode whitespace and can convert validated same-origin relative URLs into cross-origin protocol-relative URLs. Version 7.2.0 does not contain the `url.ts` file; it ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:155a38ef-f316-5371-903f-4e285ddccea1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 7.2.0-tuxcare.3 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:317c2fa9-cfbb-5877-9db0-4c71fe67bc0c",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 7.2.0-tuxcare.3 of @angular/elements. not_affected \u2014 Angular v7.2.0 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache, hierarchical HttpClient delegation (withRequestsMadeViaParent()), and automatic HTTP response caching features that were introduced in Angular v16+. Version 7.2.0 uses NgModule-based configuration (HttpClientModule) with manual TransferState only\u2014no automatic HTTP-to-TransferState caching exists. The...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:1052fcf5-ef17-576e-b922-a9d46b86584f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 7.2.0-tuxcare.3 of @angular/elements."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/elements@7.2.0-tuxcare.3"
    }
  ]
}