{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:bbbef3d2-1ff3-5ba1-9ae3-3ba7e4593927",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/localize",
      "purl": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8",
      "version": "18.1.2-tuxcare.8",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:2d82dd71-9033-5c6c-8deb-e7aaedbaaf3e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 18.1.2-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:855a3628-caf4-50c6-8b42-93ac2992e7f1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.1.2-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:4c0f760f-9dcf-54c0-b9fa-de83015b2633",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.1.2-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:90a1c7e6-e954-557e-9420-f1a10ea453c1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 18.1.2-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:ec4bc454-5207-5a15-8835-28938bb923dc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 18.1.2-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:267b92dc-3056-51bf-8065-5168f56c9ae1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.1.2-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:8badb60b-1b84-5374-9f8e-5a4991c41c45",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.1.2-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:863be930-0ea5-5238-b80d-2c534d8b8e61",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.1.2-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:3ce865e4-384a-5856-ad08-4f53698ddecc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 18.1.2-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:ff7bbf48-e654-5050-8990-d679148fb5ec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 18.1.2-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:cef2befa-8041-58f1-8e65-0b793ee531a9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 18.1.2-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:dca93dc5-2ef2-5a2a-93fb-553e2a6852fd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 18.1.2-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:fdca9f45-51eb-5a26-a04b-40144ba536b5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 18.1.2-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:739a25e1-3cab-5f98-a170-299bd440045d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 18.1.2-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:fc55dcba-8996-5e79-8d5a-0b0d8b7094ce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 18.1.2-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:3170eeb9-26fd-5387-b7ba-f154f5838b17",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50555 does not affect version 18.1.2-tuxcare.8 of @angular/localize. already_fixed \u2014 The target Angular 18.1.2 repository has already been patched for this vulnerability. TuxCare commit 32991dd728 'fix all CVEs' added a cumulative domino patch that fixes both the NOSCRIPT XSS vulnerability (CVE-2026-50556, corresponding to the provided patch f74cccd) and the astral Unicode index bug (CVE-2026-50555). The patch is applied automatically to the domino dependency via patch-package ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6451a45e-8cfe-5521-88d1-1ecef5a8f8f9",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50556 does not affect version 18.1.2-tuxcare.8 of @angular/localize. already_fixed \u2014 CVE-2026-50556 (XSS via noscript raw-text serialization in domino) has been fixed in this Angular repository. The fix is present in tools/esm-interop/patches/npm/domino+2.1.6.patch and is automatically applied to the domino dependency during installation via the postinstall script. The patch was added by TuxCare in commit 32991dd728 on 2026-07-01.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:0aaf871e-1315-5f64-8eef-3ba67f5b9980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 18.1.2-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:01e24cdc-3132-57b0-bb11-a244e8573a65",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 18.1.2-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:48e4371d-41ad-5817-a488-c14fef2b2fa6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 18.1.2-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:d7f93feb-6c39-54d2-9147-fb574c25968a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 18.1.2-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:fe7fb759-17c7-58f6-a340-b8536822ead5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 18.1.2-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:8a48f017-e0bc-528b-bbd4-bc3174e42c7a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 18.1.2-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:e4b44a61-c2d7-5ced-8157-f28030efc078",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 18.1.2-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:70301eb9-b676-5f31-805b-4852f993798a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 18.1.2-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:08a415c1-05d6-58cb-a817-80b99598a007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 18.1.2-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:9b985026-ba6e-52eb-a0f6-df72d32cabf2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 18.1.2-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6b0e0ca2-5871-5bd2-9102-92b893a74edc",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.1.2-tuxcare.8 of @angular/localize. not_affected \u2014 The target version (Angular 18.1.2) does NOT contain the vulnerable code pattern. CVE-2026-88056 describes a Unicode whitespace trimming vulnerability in Angular SSR's URL resolution, where `String.prototype.trim()` strips characters like U+00A0, converting same-origin paths into protocol-relative cross-origin URLs. The vulnerability was introduced in Angular v20.x during a refactoring (commit ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:21065511-0905-5ae3-bc85-98697653873a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 18.1.2-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:449e8b1d-47ad-5609-b1c7-d3f57c6b5089",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 18.1.2-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:c9153ebc-8921-5ac1-b455-c2449ed468e2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 18.1.2-tuxcare.8 of @angular/localize."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:9c50207a-fc09-5fb3-8a45-99c8c75f44f8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 18.1.2-tuxcare.8 of @angular/localize."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/localize@18.1.2-tuxcare.8"
    }
  ]
}