{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:bb06dfce-b35c-579c-9c4b-8ecf79ace358",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/localize",
      "purl": "pkg:npm/%40angular/localize@18.2.14-tuxcare.10",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.10",
      "version": "18.2.14-tuxcare.10",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:54ba52ec-d780-51d4-9ba7-a1a5e91e6bf0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.14-tuxcare.10 of @angular/localize."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:867429db-4a78-5bcb-88a6-ac7f4d80c96f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.2.14-tuxcare.10 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:90e631aa-ee1a-5c98-b73b-6f47c7f614be",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.2.14-tuxcare.10 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:98b8151c-fe13-58f1-af4d-09bf1c760199",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.2.14-tuxcare.10 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:52c632d4-5375-5b10-b963-08d555b47d16",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.2.14-tuxcare.10 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:4e1279d1-b7e5-5514-8ecd-4f207a25c41b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 18.2.14-tuxcare.10 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:91d14f0a-9947-5cfc-b26e-d308f70d06e2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 18.2.14-tuxcare.10 of @angular/localize, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:7331c6c3-f9bd-53d8-a5a1-45e6cd7225a7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 18.2.14-tuxcare.10 of @angular/localize, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:dc32b3bf-7883-5a20-8064-ca10f8cf56e6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 18.2.14-tuxcare.10 of @angular/localize, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:3b02e246-45d0-5dff-889e-b405c30ed16f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 18.2.14-tuxcare.10 of @angular/localize, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:33457d3b-2a87-5935-9c2c-ab70004d930c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 18.2.14-tuxcare.10 of @angular/localize, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:1f3e89a8-a4e1-5fd6-8a11-0888158ef0af",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 18.2.14-tuxcare.10 of @angular/localize, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:6b686253-2a01-5157-9d39-00f6ac5a17c6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 18.2.14-tuxcare.10 of @angular/localize, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:1aac69c0-9570-5e9e-a40a-9845194814ce",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 18.2.14-tuxcare.10 of @angular/localize, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:917a9ff8-332c-52bd-adc3-423f1548441f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 18.2.14-tuxcare.10 of @angular/localize, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:e3f6378c-a350-59f3-a7ed-5340e1b7920a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 18.2.14-tuxcare.10 of @angular/localize, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:9510b05c-acc2-55fe-8657-7c40f9a11faf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 18.2.14-tuxcare.10 of @angular/localize, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:9db51dc6-aef9-529f-b5f9-ab10d4417c19",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 18.2.14-tuxcare.10 of @angular/localize, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:f2c7d288-ad42-5de8-ae4b-31e11417019f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 18.2.14-tuxcare.10 of @angular/localize, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:074bed2e-3b93-5d8d-a3d0-e01290d584a7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 18.2.14-tuxcare.10 of @angular/localize, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:0f713dd2-4b1a-50bb-8ba6-20920ac14ed9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 18.2.14-tuxcare.10 of @angular/localize, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:ab2ee068-78be-592d-8a73-46aed6d62790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 18.2.14-tuxcare.10 of @angular/localize, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:577abbd0-ab81-5856-84b9-eaa3c3e88d97",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 18.2.14-tuxcare.10 of @angular/localize, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:bdaeaacc-6ca0-5c86-a3d9-75d1d2dbfed9",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.2.14-tuxcare.10 of @angular/localize. not_affected \u2014 The target version 18.2.14-tuxcare.13 is NOT affected by CVE-2026-88056. The vulnerable code pattern (calling String.prototype.trim() on URL strings before resolution) was never present in this version. The target uses a refactored parseUrl() implementation introduced via commit 49a60f6045 (May 2026) that correctly handles Unicode whitespace by percent-encoding it rather than stripping it, main...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:e8aa0626-ccd0-5886-8933-46221431a34d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 18.2.14-tuxcare.10 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:e80fea99-f0fb-5220-bfee-a3cde92266fe",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 18.2.14-tuxcare.10 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:5817a3ac-0db6-5922-b043-5fd8501d47d3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 18.2.14-tuxcare.10 of @angular/localize."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.10"
    }
  ]
}