{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:30b02270-4f48-566b-ad91-6f6df1cce47b",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/localize",
      "purl": "pkg:npm/%40angular/localize@18.2.14-tuxcare.5",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.5",
      "version": "18.2.14-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:aef2e1bd-dc95-5f91-b00a-61bc80054d01",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.14-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:21ae9ce7-bf87-5eb9-b0a4-eaec6da4c87e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.2.14-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:98e562d5-5da8-5bfb-8475-8c65ef954f75",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.2.14-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:dcfe50e7-fcb1-5c68-bc93-632a33f68ae9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 18.2.14-tuxcare.5 of @angular/localize, and is fixed in 18.2.14-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b8af7075-6ffa-544d-bf6d-9ac807b415ce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.2.14-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:03ddee3d-75f5-522a-98f7-a22414f21139",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 18.2.14-tuxcare.5 of @angular/localize, and is fixed in 18.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:09bc312f-395b-5bcd-832b-48947cb43fa5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 18.2.14-tuxcare.5 of @angular/localize, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c3176a6c-eeba-500b-a8e7-c41304246274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 18.2.14-tuxcare.5 of @angular/localize, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e824001e-4b02-5e9a-839b-55d80ded0003",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 18.2.14-tuxcare.5 of @angular/localize, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:41dab16d-da05-5c98-afb0-85206daed43b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 18.2.14-tuxcare.5 of @angular/localize, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d102a384-c1d3-51ea-81b0-81d2dfe15f20",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 18.2.14-tuxcare.5 of @angular/localize, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0b722f16-466f-5b16-b4c9-3f2f00ece3d1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 18.2.14-tuxcare.5 of @angular/localize, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6503dad1-3a2f-5691-b7a7-47b317659954",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 18.2.14-tuxcare.5 of @angular/localize, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:daa1489f-1fe6-55d2-9853-1221c378ece8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 18.2.14-tuxcare.5 of @angular/localize, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:cd077656-0fd8-5dad-9e46-defd0c46733e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 18.2.14-tuxcare.5 of @angular/localize, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c1f51de1-16ee-5dad-94fc-885aae61c4b1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 18.2.14-tuxcare.5 of @angular/localize, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d8e7eabb-2e92-5ee2-83bf-f4a3df1d6679",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 18.2.14-tuxcare.5 of @angular/localize, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e4762dcf-34cb-574a-87f0-b8c70d4983e8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 18.2.14-tuxcare.5 of @angular/localize, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:78f13592-792e-5631-9b91-e630ae0d7506",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 18.2.14-tuxcare.5 of @angular/localize, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:604b574d-3f24-5dd4-b6ca-d0c80b66ec7c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 18.2.14-tuxcare.5 of @angular/localize, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:dd4f14eb-5512-51c7-8b34-65de01496c8a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 18.2.14-tuxcare.5 of @angular/localize, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:59dfd53f-59e6-5a7b-8803-e42e30d677d4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 18.2.14-tuxcare.5 of @angular/localize, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b0e27857-57de-560e-bfb2-4eb260fe8ae0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 18.2.14-tuxcare.5 of @angular/localize, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:69159223-b564-573d-a115-5ca9c38f1147",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.2.14-tuxcare.5 of @angular/localize. not_affected \u2014 The target version 18.2.14-tuxcare.13 is NOT affected by CVE-2026-88056. The vulnerable code pattern (calling String.prototype.trim() on URL strings before resolution) was never present in this version. The target uses a refactored parseUrl() implementation introduced via commit 49a60f6045 (May 2026) that correctly handles Unicode whitespace by percent-encoding it rather than stripping it, main...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:235c04b2-1c24-5672-8b23-cb4d522feb80",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 18.2.14-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d3dff900-9a61-5302-962d-56cf4bfb278a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 18.2.14-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3c98fd7b-e22d-5cff-b5f7-e1d55f09c047",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 18.2.14-tuxcare.5 of @angular/localize."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.5"
    }
  ]
}