{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7bc9d640-3155-5506-96cd-d1a04d317962",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/localize@18.2.12-tuxcare.4",
      "type": "library",
      "name": "@angular/localize",
      "version": "18.2.12-tuxcare.4",
      "purl": "pkg:npm/%40angular/localize@18.2.12-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:30de29bf-b9d2-5269-9405-519bb15f6924",
      "id": "CVE-2025-59052",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 18.2.12-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04b20ac0-d432-5980-81e0-b9084ba129ca",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.12-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0cb43d5-5f3b-55ad-ac4b-6c7408abdce6",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.2.12-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fd3cda3-814f-515d-83d7-377906aa3527",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.2.12-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac5eb466-4cbe-5c45-94b1-541eabf00a0a",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.2.12-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5dbe523d-aa40-52a9-8c54-79a0592d3d97",
      "id": "CVE-2026-32635",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.2.12-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ed7b660-6e1e-559a-aa27-ed4683f6c3c0",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 18.2.12-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28561318-1c71-5c98-9845-ac3988ca3f8e",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 18.2.12-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b7956cb-328e-5285-ac5b-7de1518c4e9f",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 18.2.12-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f541f0b-a875-5b18-86a4-175cdaf61583",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 18.2.12-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f1de958-d71d-57b1-9fef-f21de59e25db",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 18.2.12-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62e456d8-cc6b-5889-9fb4-93e86089f2a7",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 18.2.12-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3bc80ebe-d21a-5555-85fd-e86c35326aba",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 18.2.12-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7beda40-041f-54cc-8255-4887178c5ccc",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50555 does not affect version 18.2.12-tuxcare.4 of @angular/localize. already_fixed \u2014 CVE-2026-50555 fix is already present in the target repository. The vulnerability concerns XSS in domino's noscript element serialization. The fix (escaping matching closing tags and adding NOSCRIPT to raw-text element handling) exists as a patch file that is automatically applied during yarn install via patch-package."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad7e2d3c-4773-5a17-9bf6-535d26693210",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50556 does not affect version 18.2.12-tuxcare.4 of @angular/localize. already_fixed \u2014 CVE-2026-50556 (XSS via <noscript> raw-text serialization in domino) has been fixed. The target repository contains a committed patch file (tools/esm-interop/patches/npm/domino+2.1.6.patch) that applies the complete fix to the domino dependency. The patch adds NOSCRIPT to the hasRawContent set and removes the conditional _scripting_enabled check, matching the upstream fix exactly. This patch is..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04d1e613-c4c0-5dbc-a4dc-c503660fadd6",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 18.2.12-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0025bf8-e919-524f-aa89-351a0e17b7bc",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 18.2.12-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf653ee6-de6c-52b6-b6fd-62f46662e8e2",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 18.2.12-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:786a9e98-cc81-5cda-9ed8-90f4d33aff56",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 18.2.12-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b585008-174c-5f3c-87b4-ca34d6b6aa36",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 18.2.12-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5602a2a3-89b6-5fda-afdb-d781a421700b",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 18.2.12-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5b09e9d-5e11-58f8-bd28-74758c3726ac",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 18.2.12-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42f8b0bc-74eb-52ea-99c1-dc9c70058f75",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 18.2.12-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e87aadc3-feda-5a15-8223-5b02e2f64498",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 18.2.12-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52329656-7e85-5174-8fa0-4ead284fc83c",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 18.2.12-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@18.2.12-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/localize@18.2.12-tuxcare.4"
    }
  ]
}