{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9cd72913-5529-5515-855a-35000c9e0783",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/localize",
      "purl": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5",
      "version": "16.2.11-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8ee55412-2d45-5a30-a373-22f9ca92b7af",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 16.2.11-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a433e81b-a67b-5e0b-8c07-8fd91731da96",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.11-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ad3afc6e-e893-5d34-ba9b-6c3407764d95",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 16.2.11-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9dc2771e-cd85-5f32-8a06-591fa87e99db",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 16.2.11-tuxcare.5 of @angular/localize, and is fixed in 16.2.11-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5dcc1664-b034-5aaf-8cfb-476bd1a6dca9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 16.2.11-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:53effd39-51c6-58cf-8b31-6c3482223156",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 16.2.11-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6d344c1e-84ae-515e-bdff-1d10be734989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 16.2.11-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:28f99f1b-0fa6-56ef-9a7e-48bf86a324fc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 16.2.11-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b010f19c-8307-5bfc-9837-5c90bac7e028",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 16.2.11-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4bf253c5-7265-5461-93e4-1e5cfba8a50d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 16.2.11-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f13a0e50-160d-55b9-ac48-e595005554ba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 16.2.11-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c69a2ef7-50eb-5b62-b904-69d4821a7be3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 16.2.11-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:12414aca-b988-5497-81be-255bc0c1cfcd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 16.2.11-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6b61507c-1b0a-5fc7-92ec-68c0f41c1ba7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 16.2.11-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:849240eb-1500-50b0-8b04-b43430a69ba3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 16.2.11-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2919e8c9-3ed0-5e8f-94b4-c0da073af606",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 16.2.11-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b4a2a8ba-8310-5d71-836f-42e09c5c3171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 16.2.11-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:78b87219-ce96-5809-a11d-df3b1679a4f1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 16.2.11-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b2c9f102-3a49-58b3-b82a-aad9dc5ebf89",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 16.2.11-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:26f6748c-0a9e-563a-ba09-8609453cc8e3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 16.2.11-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c1bc4227-72be-51a2-9bb9-abb0eedc51bd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 16.2.11-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e1c10b8a-a1cd-5bf1-9b4f-5476c4f12739",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 16.2.11-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0ff430c0-351a-51f0-a802-3efbf6be3cd5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 16.2.11-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d363db4d-4143-50ee-a302-5b0f9a352e86",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 16.2.11-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:52997a4c-2bd2-505f-90f1-bf83e86a7f12",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 16.2.11-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:25147ebf-65a3-558a-96a7-227c07afb9bd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 16.2.11-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2ac6d1ed-a0d6-56b4-9ad3-ef70ad697c6b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.11-tuxcare.5 of @angular/localize. not_affected \u2014 Angular 16.2.11-tuxcare.2 is NOT affected by CVE-2026-88056. The vulnerability requires WHATWG URL validation combined with String.prototype.trim() on URLs during SSR, creating a discrepancy that enables SSRF. While the target uses WHATWG URL parsing (backported in commit c03fbfd7cc for CVE-2026-50168), it does NOT call String.prototype.trim() on URLs. The attack chain is broken at the trim() s...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:00da2adf-36cc-583f-8f0a-c57ca5377541",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 16.2.11-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d8b03290-5316-583b-ab52-68064f968837",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 16.2.11-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:20294f02-6b26-501d-9e70-7617a8048a9c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 16.2.11-tuxcare.5 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2bb8779d-2ba6-563e-8351-0731c613a5ed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 16.2.11-tuxcare.5 of @angular/localize."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/localize@16.2.11-tuxcare.5"
    }
  ]
}