{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:48d911cd-b94f-597d-890c-d7f17745307a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/localize@14.2.12-tuxcare.2",
      "type": "library",
      "name": "@angular/localize",
      "version": "14.2.12-tuxcare.2",
      "purl": "pkg:npm/%40angular/localize@14.2.12-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f2319664-4a0f-5d2a-a533-9ff9f9759b50",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 14.2.12-tuxcare.2 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@14.2.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3290ca4-b18f-5295-80de-eedff5fdba5e",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 14.2.12-tuxcare.2 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@14.2.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb8e3258-5971-52d1-a023-b005a63142a0",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 14.2.12-tuxcare.2 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@14.2.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a481c90-ef85-51fa-9f3e-1a54a74a3fa8",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 14.2.12-tuxcare.2 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@14.2.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f57d99b-d30f-52ae-8f31-52886181d27a",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 14.2.12-tuxcare.2 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@14.2.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90a22ede-1f07-5e90-bf67-666346a67edc",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 14.2.12-tuxcare.2 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@14.2.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a3fcf15-57c3-5ef7-9a8a-d89a1f0e1f19",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 14.2.12-tuxcare.2 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@14.2.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f790c1b6-8855-5c1c-9b6b-cb19fdbb8dac",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 14.2.12-tuxcare.2 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@14.2.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d558ed11-696c-5fa3-b52e-4ec37bc50b5e",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50170 does not affect version 14.2.12-tuxcare.2 of @angular/localize. not_affected \u2014 Angular v14.2.12-tuxcare.1 is not affected by CVE-2026-50170. The HTTP TransferCache feature and client hydration mechanism that contain the vulnerability were introduced in Angular v16+. This version predates that feature introduction and does not have the vulnerable code path."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@14.2.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ae5f7b2-58a6-521a-aa48-43ec9ace3b50",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 14.2.12-tuxcare.2 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@14.2.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adbabdd2-b882-52c8-968b-6924e86379bd",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 14.2.12-tuxcare.2 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@14.2.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d2f1c08-9578-5473-b467-0ae360d6d777",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 14.2.12-tuxcare.2 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@14.2.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2f7e7e7-c75f-5f3e-af6b-3b0dd006d8ae",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 14.2.12-tuxcare.2 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@14.2.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef4d7f3a-4eb6-5f93-aa53-f914ce843937",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 14.2.12-tuxcare.2 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@14.2.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab904212-fb52-5247-a32c-8a0da1e6479d",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 14.2.12-tuxcare.2 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@14.2.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54716085-25f5-5409-a4f2-92fc92fa4722",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 14.2.12-tuxcare.2 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@14.2.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c076ae5-f545-5d38-8958-f064dc44e7d6",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 14.2.12-tuxcare.2 of @angular/localize. not_affected \u2014 Angular 14.2.12-tuxcare.1 is not affected by CVE-2026-54265. This version uses the pre-pipeline compiler architecture where two-way bindings are desugared into separate property and event bindings, both of which go through proper sanitization. The vulnerability only exists in Angular 17.3.0+ where the template pipeline with TwoWayProperty IR operation was introduced."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@14.2.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d2d9965-ecf1-5ebb-a0d7-1101a1bc5c0d",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54266 does not affect version 14.2.12-tuxcare.2 of @angular/localize. not_affected \u2014 Angular 14.2.12 is not affected by CVE-2026-54266. The vulnerable HttpTransferCache feature does not exist in this version - it was introduced in Angular v16+. The target has no code path that generates cache keys from HTTP request parameters, and therefore cannot experience cache key collisions."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@14.2.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:754c965c-c78c-513a-b03a-08aab034bbea",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 14.2.12-tuxcare.2 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@14.2.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65f24181-3839-59ec-b54a-861e415c87a4",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 14.2.12-tuxcare.2 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@14.2.12-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/localize@14.2.12-tuxcare.2"
    }
  ]
}