{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:17d457d3-18f0-52f7-95c3-efc47a6ae39e",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/localize",
      "purl": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6",
      "version": "17.1.0-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c31a59d8-e027-5ebd-9908-a03531a2287d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.1.0-tuxcare.6 of @angular/localize."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:26db59b7-97db-5725-9cbf-ce999fb2d3dd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.1.0-tuxcare.6 of @angular/localize."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2138f959-50ab-53a9-b31e-f15c123de375",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.1.0-tuxcare.6 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ffd58199-60d3-5716-a341-c2cfb4863190",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.1.0-tuxcare.6 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e801c712-f770-53b3-9d22-e80b635697af",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.1.0-tuxcare.6 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:75baf43c-f11c-503f-b5af-7860bce849f0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.1.0-tuxcare.6 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f7c37a46-5f1d-5fb9-8845-24f325c51db5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 17.1.0-tuxcare.6 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1257ad56-f10d-5c31-a00d-8dbfd3220d3c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.1.0-tuxcare.6 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f8e07e18-e008-5154-9905-62ddb1dbf0c7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.1.0-tuxcare.6 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ce64f74e-e702-5ef9-bb60-324ee784840f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.1.0-tuxcare.6 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9be078d9-96ff-5256-a756-ec752702f2d9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.1.0-tuxcare.6 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f0ddbdee-148a-5d45-8e7b-a44d0a62e47a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.1.0-tuxcare.6 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:73e55b68-7398-5bc6-afea-37acdb8c184b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.1.0-tuxcare.6 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b3d94dfc-110e-5e18-ab0a-59a639e61e81",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.1.0-tuxcare.6 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:20908e5d-76a8-59f8-8d6d-fb8e9217da4b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.1.0-tuxcare.6 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b1fe8fc6-6d87-578a-a2a7-5f9e93eb667e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.1.0-tuxcare.6 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2d0b0e60-815e-5277-8d08-29d27701f31c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.1.0-tuxcare.6 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:aef85e15-80ef-5033-a54d-181702188af4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.1.0-tuxcare.6 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:57c4fa7a-5bfa-5300-add6-c5eccaa304d2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 17.1.0-tuxcare.6 of @angular/localize. not_affected \u2014 Angular v17.1.0 does not have the TwoWayProperty IR operation that is the subject of CVE-2026-54265. Two-way bindings are desugared into separate property and event bindings before template pipeline processing, with the property half using the same parsePropertyBinding() code path as one-way property bindings, which are properly sanitized.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:99601393-e5a3-5a4a-8a5d-42ab23d694d5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.1.0-tuxcare.6 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:aebdc5d7-8846-53fb-83c2-1eb4229063a3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.1.0-tuxcare.6 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:af158e5c-eeab-5042-93ad-166689c1776b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.1.0-tuxcare.6 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9ab5b484-9e14-514b-bdd3-e7f02456385f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 17.1.0-tuxcare.6 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3d52519f-dce4-5b06-b7de-0801364f41cb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 17.1.0-tuxcare.6 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a32e1a4d-3f1d-5af3-b4e7-e73a1eb70206",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 17.1.0-tuxcare.6 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:151d6103-5091-5308-9650-5b8fdd5be23a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.1.0-tuxcare.6 of @angular/localize. not_affected \u2014 Angular 17.1.0 was never vulnerable to CVE-2026-88056. The vulnerability exists only in newer Angular versions (v18+, v19+, v20+ before fixes) where a url.ts file with a parseUrl function that uses String.prototype.trim() was introduced. Angular 17.1.0 does not have this file in the upstream release. TuxCare created url.ts for their 17.1.0 fork (commit e06d36f339 by ejarocki@cloudlinux.com) but...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a13472f3-74b3-5130-afe7-c70c9ff639fd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 17.1.0-tuxcare.6 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:eed2bc79-b604-562b-a175-25d9ff592647",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88058 does not affect version 17.1.0-tuxcare.6 of @angular/localize. not_affected \u2014 The Angular repository (version 17.1.0-tuxcare.5 at SHA 1b802ce320) is not affected by CVE-2026-88058 because it does not contain the vulnerable source code. The vulnerability exists in the domino library's HTML serialization code (lib/NodeUtils.js), which Angular references as a dependency in package.json but does not vendor. The upstream patch (89b20568dfaee1ec8e0b3bcf1872acdddd2f4fef) is a D...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a8f81065-1902-52a8-afff-84052aa5d271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 17.1.0-tuxcare.6 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4a1f2ea4-d76d-55fc-a72a-3433c2a699d4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 17.1.0-tuxcare.6 of @angular/localize."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/localize@17.1.0-tuxcare.6"
    }
  ]
}