{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:041e8774-cd93-57ca-88f1-8acb32164306",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/localize",
      "purl": "pkg:npm/%40angular/localize@18.2.14-tuxcare.8",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.8",
      "version": "18.2.14-tuxcare.8",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f4b7b3f0-a7bb-592e-a6ba-58cbfa0985c3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.14-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:d1534078-992d-56ef-ada5-52b43c312be3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.2.14-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:c4396f49-edb8-55bc-a4b3-8e2bcc533511",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.2.14-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:5770b9f3-7e08-572c-a12d-6bfa61e2da3d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.2.14-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:79002074-d17d-591f-99f6-468a0df2b51b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.2.14-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:c2aedd16-1a9c-505b-86f0-7246864e6282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 18.2.14-tuxcare.8 of @angular/localize, and is fixed in 18.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:4090a07e-3581-50a4-8dde-1e6252d2382d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 18.2.14-tuxcare.8 of @angular/localize, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:b6b6f9f9-920f-5107-a595-9a1950716eb2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 18.2.14-tuxcare.8 of @angular/localize, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:df8b2bba-ab65-513d-a102-8d50132cff99",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 18.2.14-tuxcare.8 of @angular/localize, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:e3e03eed-d513-50be-aff5-927c7a40381a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 18.2.14-tuxcare.8 of @angular/localize, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:851a310d-69c1-5d14-a965-e9b3ce54a5ac",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 18.2.14-tuxcare.8 of @angular/localize, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:8972d6bc-747e-5439-97e4-792b5f6f3b42",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 18.2.14-tuxcare.8 of @angular/localize, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:5873f23d-34f1-5731-9617-bd1b8ba6497c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 18.2.14-tuxcare.8 of @angular/localize, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:183e4749-d939-5a59-8405-19b3849fb995",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 18.2.14-tuxcare.8 of @angular/localize, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6cbcb541-387a-5940-a2a7-47b9fa24b809",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 18.2.14-tuxcare.8 of @angular/localize, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:0f5a39bd-ea51-54e9-a45d-dc0321e2772e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 18.2.14-tuxcare.8 of @angular/localize, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:4793a399-1a77-5c41-a888-91c88fe1c3ca",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 18.2.14-tuxcare.8 of @angular/localize, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:3685ec2b-cd55-5176-9305-8ebd61b43487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 18.2.14-tuxcare.8 of @angular/localize, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:5e353784-f517-5c87-9a24-a650cbf31064",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 18.2.14-tuxcare.8 of @angular/localize, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:d90a4f32-2462-5296-8358-324fbb286682",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 18.2.14-tuxcare.8 of @angular/localize, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:c2b266b2-1f75-5801-8186-c4bfc9054789",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 18.2.14-tuxcare.8 of @angular/localize, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f6452968-37dc-5c41-9c76-a381dbacb6b1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 18.2.14-tuxcare.8 of @angular/localize, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:fcf4d0e5-6dc4-56bf-a403-2823838a89eb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 18.2.14-tuxcare.8 of @angular/localize, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:743b0294-21e4-55a8-9f33-dd226369ce46",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.2.14-tuxcare.8 of @angular/localize. not_affected \u2014 The target version 18.2.14-tuxcare.13 is NOT affected by CVE-2026-88056. The vulnerable code pattern (calling String.prototype.trim() on URL strings before resolution) was never present in this version. The target uses a refactored parseUrl() implementation introduced via commit 49a60f6045 (May 2026) that correctly handles Unicode whitespace by percent-encoding it rather than stripping it, main...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:18986dd6-5e3b-5e98-9155-a2d4a4319fce",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 18.2.14-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:a801c0e0-0a42-5d3e-bf9d-396530223e7c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 18.2.14-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:19405478-bcbd-5fac-8ab2-87b10317ab54",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 18.2.14-tuxcare.8 of @angular/localize."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/localize@18.2.14-tuxcare.8"
    }
  ]
}