{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4784f095-9a2c-563e-b351-9c67480096da",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/localize",
      "purl": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4",
      "version": "16.2.11-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:15a332cb-5d84-5649-8ca4-b5c14ae7cf6a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 16.2.11-tuxcare.4 of @angular/localize."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:92e558fb-ff13-52bf-a2d3-a9cfcf847892",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.11-tuxcare.4 of @angular/localize."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c2600e7a-d679-5211-bccf-221bcf9d5f33",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 16.2.11-tuxcare.4 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b497fd0b-a9d2-5449-a4b6-15b4f18891e6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 16.2.11-tuxcare.4 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:aa751315-83c6-5336-9241-4051d02cb4fa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 16.2.11-tuxcare.4 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9ec8f729-70ef-5561-95f1-f29014863363",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 16.2.11-tuxcare.4 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:fab7473e-7aa1-5c28-a569-8c7194dc9825",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 16.2.11-tuxcare.4 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:524e3643-3728-5d8e-9430-d71e75f33e52",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 16.2.11-tuxcare.4 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e215c4ee-2645-5b67-ab8a-be52ceb0961e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 16.2.11-tuxcare.4 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6c1e72dc-9943-57aa-8e2e-450fc561e806",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 16.2.11-tuxcare.4 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d5b6f791-ab13-520c-8f72-6ff2eb147992",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 16.2.11-tuxcare.4 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7def6895-b7f5-5cce-a96d-cb5fd896fb1c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 16.2.11-tuxcare.4 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:231bc5f5-e094-55c5-a1ea-957029fa496d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 16.2.11-tuxcare.4 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9890c447-41e9-5085-b2fe-8e05e52eceb7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 16.2.11-tuxcare.4 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:92abf26d-9e30-59dc-9624-8c2af6f5c2c6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 16.2.11-tuxcare.4 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c8a9e7d9-8e85-549f-b23b-e2bfa416a349",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 16.2.11-tuxcare.4 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6336c360-bc06-558a-baca-d3298d3b5061",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 16.2.11-tuxcare.4 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:bd51523c-b105-5661-bdfd-f7b5af6e6714",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 16.2.11-tuxcare.4 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ef7a2da7-fd79-5240-9868-f56852a38c4f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 16.2.11-tuxcare.4 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7c5d021b-fc25-5dd3-8ea0-4d797f090b5a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 16.2.11-tuxcare.4 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:573d1df4-4716-5061-83bb-28e65ca47e49",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 16.2.11-tuxcare.4 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8e55da62-d350-5ba1-80dd-9c258a2b9465",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 16.2.11-tuxcare.4 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:bdd725c3-505e-5a89-9add-b17b8957fdd8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 16.2.11-tuxcare.4 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:598a262a-8534-55ee-ae53-365d3d741aaa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 16.2.11-tuxcare.4 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ffd5a337-1900-53c2-a1ab-58134ccb81b5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 16.2.11-tuxcare.4 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:81af9137-3384-5677-b753-f208a6ba0257",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.11-tuxcare.4 of @angular/localize. not_affected \u2014 Angular 16.2.11-tuxcare.2 is NOT affected by CVE-2026-88056. The vulnerability requires WHATWG URL validation combined with String.prototype.trim() on URLs during SSR, creating a discrepancy that enables SSRF. While the target uses WHATWG URL parsing (backported in commit c03fbfd7cc for CVE-2026-50168), it does NOT call String.prototype.trim() on URLs. The attack chain is broken at the trim() s...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:95a56865-c76c-5f92-abe1-0df497d54a09",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 16.2.11-tuxcare.4 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:45c51460-cf43-5a72-90d5-0b9d61b483e0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 16.2.11-tuxcare.4 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:15efc19d-60ce-5c4a-b51d-0f11f59cfef8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 16.2.11-tuxcare.4 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a1d49911-1b19-5197-946b-1a0b87ed9693",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 16.2.11-tuxcare.4 of @angular/localize."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.4"
    }
  ]
}