{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2f7e5002-4738-51ca-afac-bfa845b0a0fa",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/localize",
      "purl": "pkg:npm/%40angular/localize@16.2.12-tuxcare.3",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/localize@16.2.12-tuxcare.3",
      "version": "16.2.12-tuxcare.3",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.12-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:c6b40a9b-b257-5216-a554-fa57c7e6280b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 16.2.12-tuxcare.3 of @angular/localize."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.12-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:ae5a6e0e-49f7-51d7-8481-fcec5b6cb804",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.12-tuxcare.3 of @angular/localize."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.12-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:4003b1cf-8946-579e-a463-f45319a7808b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 16.2.12-tuxcare.3 of @angular/localize, and is fixed in 16.2.12-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.12-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:2ce2b6fe-6526-5495-a9ff-13fddf8b4082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 16.2.12-tuxcare.3 of @angular/localize, and is fixed in 16.2.12-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.12-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:6908f258-57af-520f-bc9c-659e965c7dec",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 16.2.12-tuxcare.3 of @angular/localize, and is fixed in 16.2.12-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.12-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:11bbd65e-1a5a-589d-9ddd-ca474be3f2e0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 16.2.12-tuxcare.3 of @angular/localize, and is fixed in 16.2.12-tuxcare.10."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.12-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:92df3dee-c17f-5334-aa8a-25d2859da150",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 16.2.12-tuxcare.3 of @angular/localize, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.12-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:3e1c6566-5a26-5bdf-a85d-575ed3962cdd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 16.2.12-tuxcare.3 of @angular/localize, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.12-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:f4d39c3a-8085-526f-8331-9e43e4310f12",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 16.2.12-tuxcare.3 of @angular/localize, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.12-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:e8106953-4b55-5c91-9049-793f45c1d4fa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 16.2.12-tuxcare.3 of @angular/localize, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.12-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:08aaa4cf-ba7b-5251-9da4-b3f86e45ba12",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 16.2.12-tuxcare.3 of @angular/localize, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.12-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:2d9ab549-6d43-5b82-b6e9-adc870678596",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 16.2.12-tuxcare.3 of @angular/localize, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.12-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:6789660c-1480-5e5a-8d80-111c202fc9f6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 16.2.12-tuxcare.3 of @angular/localize, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.12-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:a41b085d-708c-5b03-96b0-092144b7e660",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 16.2.12-tuxcare.3 of @angular/localize, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.12-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:519149b6-c765-502a-a4d2-540c9fc5da14",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 16.2.12-tuxcare.3 of @angular/localize, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.12-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:24487f66-0994-5980-8689-41aec0039117",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 16.2.12-tuxcare.3 of @angular/localize, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.12-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:899c0c47-a429-5cc9-9774-069228eab18e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 16.2.12-tuxcare.3 of @angular/localize, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.12-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:12c25ca0-8cf5-5c6d-ae25-691f03d05fd6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 16.2.12-tuxcare.3 of @angular/localize, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.12-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:80ebaaae-c3d4-595a-b3d1-dd769fc48457",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 16.2.12-tuxcare.3 of @angular/localize, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.12-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:6b57c76a-430e-5357-a8e0-b8b0c7628a71",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 16.2.12-tuxcare.3 of @angular/localize, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.12-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:38eab6bc-0941-5d6a-bd6a-bfcbbb213644",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 16.2.12-tuxcare.3 of @angular/localize, and is fixed in 16.2.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.12-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:55986fd9-72dd-5e92-9481-0c2db0eb7f41",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 16.2.12-tuxcare.3 of @angular/localize, and is fixed in 16.2.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.12-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:d4160953-91d5-54e0-8efa-1764fb71068a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 16.2.12-tuxcare.3 of @angular/localize, and is fixed in 16.2.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.12-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:530744dc-a3ea-5202-924d-5a70addb2b5c",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.12-tuxcare.3 of @angular/localize. not_affected \u2014 CVE-2026-88056 affects Angular versions 20.3.x, 21.2.x, and 22.x where a refactored URL parsing utility added String.prototype.trim() that strips Unicode whitespace, enabling SSRF bypasses. The target (Angular 16.2.12-tuxcare.12) is based on Angular 16.2.x architecture, which predates the vulnerable code pattern entirely. TuxCare created url.ts fresh on June 24, 2026 for CVE-2026-50168, modelin...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.12-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:10f1c431-c7f5-5716-9c3e-9b1e7b907046",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 16.2.12-tuxcare.3 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.12-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:5a9f137f-cc8d-5ac6-8d1a-aa4b150d4a53",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 16.2.12-tuxcare.3 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.12-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:b39580c2-0fe4-5f29-8435-abc316e9f8ed",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 16.2.12-tuxcare.3 of @angular/localize."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/localize@16.2.12-tuxcare.3"
    }
  ]
}