{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:798bb74d-2dfa-5e1c-83f3-f948844f9e56",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/localize",
      "purl": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1",
      "version": "17.3.12-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:671d45b3-0854-5d21-a67d-a8a76d559a18",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 17.3.12-tuxcare.1 of @angular/localize, and is fixed in 17.3.12-tuxcare.3."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:45b07883-6f66-5245-83fd-e7c59a1ef34c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 17.3.12-tuxcare.1 of @angular/localize, and is fixed in 17.3.12-tuxcare.3."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5ee45e50-0036-5e8d-aa20-f328d8fab018",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 17.3.12-tuxcare.1 of @angular/localize, and is fixed in 17.3.12-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0a7551bd-3da3-58c7-8b19-5a1780730728",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 17.3.12-tuxcare.1 of @angular/localize, and is fixed in 17.3.12-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c5b94bdd-07e8-5aa6-8810-295a9844e944",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 17.3.12-tuxcare.1 of @angular/localize, and is fixed in 17.3.12-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:624b8555-4b48-5a79-b1cf-db2eaa11c89e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32635 affects version 17.3.12-tuxcare.1 of @angular/localize, and is fixed in 17.3.12-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9af60222-a957-5f71-b71a-bb8d95ded1fa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 17.3.12-tuxcare.1 of @angular/localize, and is fixed in 17.3.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:986daeae-084d-5c1a-9f14-f0f6df293d93",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 17.3.12-tuxcare.1 of @angular/localize, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0c244a3f-5851-548e-99ac-800e0f9ddead",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 17.3.12-tuxcare.1 of @angular/localize, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8495baeb-e671-5f0e-a809-812188a5b031",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 17.3.12-tuxcare.1 of @angular/localize, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4656922e-c465-5846-af28-148174290dbe",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 17.3.12-tuxcare.1 of @angular/localize, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:33cf7b19-d2a0-5004-81f5-4c7dffe07015",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 17.3.12-tuxcare.1 of @angular/localize, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b75d0c24-2a23-5762-9a63-1c2c4a2a81ce",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 17.3.12-tuxcare.1 of @angular/localize, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:42f7c995-b9d6-5d36-896e-23bd2413c905",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 17.3.12-tuxcare.1 of @angular/localize, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e107b643-0458-5f32-acf1-2a90da14f95b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 17.3.12-tuxcare.1 of @angular/localize, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0bd87b7d-ab8b-51d7-97a5-54dfb0c42f1a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 17.3.12-tuxcare.1 of @angular/localize, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d065f7bb-8690-5a3a-84a7-8ad26e9c3893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 17.3.12-tuxcare.1 of @angular/localize, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5cbb25bb-6347-5004-aaaf-3c59343d15f5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 17.3.12-tuxcare.1 of @angular/localize, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:645eded2-5e52-570f-85c4-4fa791c93ccc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 17.3.12-tuxcare.1 of @angular/localize, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:508ab842-9c98-52b0-85e4-b3cd7f7ca149",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 17.3.12-tuxcare.1 of @angular/localize, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:76cd2533-e1a1-50cd-a0e2-8ea96b4ed910",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 17.3.12-tuxcare.1 of @angular/localize, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:522e83b5-2a01-52fe-8a58-fdb6165f93fb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 17.3.12-tuxcare.1 of @angular/localize, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ef131bb2-0dd5-53a0-b2bc-62a90d7ab8f2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 17.3.12-tuxcare.1 of @angular/localize, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:16ffbf99-4022-5c78-9e32-2e341d81ea31",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 17.3.12-tuxcare.1 of @angular/localize, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c1903f55-fb32-5c94-b9bf-fac0db2f4b4e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.3.12-tuxcare.1 of @angular/localize. not_affected \u2014 Version 17.3.12 is not affected by CVE-2026-88056. The vulnerability involves String.prototype.trim() being applied during URL resolution in Angular's platform-server, converting validated same-origin URLs with Unicode whitespace into cross-origin protocol-relative URLs, leading to SSRF. This vulnerable code pattern was introduced in newer Angular versions (v20+) and does not exist in version 1...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ad928448-8480-5a4e-87a5-d3e3b3ad27a2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 17.3.12-tuxcare.1 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f205a479-a6cf-51d8-b38b-332919a946f9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 17.3.12-tuxcare.1 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:21c3f152-dd67-523b-8dc3-c3d528b4e1c2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 17.3.12-tuxcare.1 of @angular/localize."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/localize@17.3.12-tuxcare.1"
    }
  ]
}