{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:df3f6f26-dff3-53d7-b5db-6c46ec8ca6b6",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/localize@12.0.0-tuxcare.4",
      "type": "library",
      "name": "@angular/localize",
      "version": "12.0.0-tuxcare.4",
      "purl": "pkg:npm/%40angular/localize@12.0.0-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:920a5413-b4e6-5e05-978b-eb44f89d5a7d",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 12.0.0-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@12.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42f953a9-1d0c-51cb-93c2-5cd22b6c7d2f",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 12.0.0-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@12.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:baf51b25-f6ae-53d0-be71-20d5a03e27ac",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 12.0.0-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@12.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54c63ca3-7aa6-5bd5-a1a4-5b3a9babe509",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 12.0.0-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@12.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61eb78cb-ceaf-59ad-bf5f-f17246720d2b",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41423 does not affect version 12.0.0-tuxcare.4 of @angular/localize. not_affected \u2014 The target repository (Angular v12.0.0-tuxcare.2) is not affected by CVE-2026-41423. This version uses Node.js url.parse() for URL parsing, which does not exhibit the hostname override vulnerability. The CVE affects Angular versions 21.0.4+ where the codebase was refactored to use the URL constructor with a base parameter, allowing protocol-relative URLs (//evil.com) to override the hostname. T..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@12.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58170ced-3e5a-5601-9923-980daf30aafe",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 12.0.0-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@12.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fd8c3df-746a-52ee-96b9-7fa9323c2e6f",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 12.0.0-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@12.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45bd6627-9a63-5798-88fe-2b924fefc432",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 12.0.0-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@12.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8216575d-b41b-5dbe-bc43-fb70ff09318b",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50170 does not affect version 12.0.0-tuxcare.4 of @angular/localize. not_affected \u2014 Angular v12.0.0-tuxcare.2 is not affected by CVE-2026-50170. The HTTP transfer cache feature that contains the vulnerability does not exist in this version. The transfer cache was introduced in Angular v16+, while this is version 12."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@12.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90059b4b-eea9-52f1-8f39-522851e79ada",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 12.0.0-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@12.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfdd82c9-1c1f-5a1f-b162-9b877ee8d7ed",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 12.0.0-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@12.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2cbe00d-1a83-5dc9-928c-b9b27586daa4",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 12.0.0-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@12.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:540d5058-9c00-52ba-b03a-176d3037581c",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 12.0.0-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@12.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24fb7333-4bda-53dc-94cc-d73c84243e47",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 12.0.0-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@12.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:534afde8-d1b9-53a2-a737-5cb45b0a5c4f",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 12.0.0-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@12.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26eb976c-2313-59bf-846a-182167c41f87",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54264 does not affect version 12.0.0-tuxcare.4 of @angular/localize. not_affected \u2014 Angular version 12.0.0 is not affected by CVE-2026-54264. The service worker's AssetGroup class does not preserve request headers when making network requests, including on cross-origin redirects. Version 12.0.0 predates the architectural change that introduced metadata preservation (including headers), which was later found to be vulnerable in versions 20.x-22.x."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@12.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a71fa8a6-1f59-5692-84e2-f55e45de5c62",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 12.0.0-tuxcare.4 of @angular/localize. not_affected \u2014 Angular 12.0.0-tuxcare.2 is not affected by CVE-2026-54265. The vulnerability is specific to the Ivy template pipeline architecture with TwoWayProperty IR operations (introduced in Angular 20+). Angular 12 uses a different architecture where two-way bindings are desugared at parse time into separate property and event bindings, and the property binding is sanitized through the same code path as..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@12.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc860163-43da-59fe-ba40-1cb5dc525726",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54266 does not affect version 12.0.0-tuxcare.4 of @angular/localize. not_affected \u2014 Angular v12.0.0-tuxcare.2 is not affected by CVE-2026-54266. The HttpTransferCache feature containing the weak DJB2 hash vulnerability does not exist in this version - it was introduced in Angular v16+."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@12.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f741530f-8066-593f-ae76-8c1f29ab671e",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 12.0.0-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@12.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b4c37a2-b764-5955-b939-57253eafc782",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 12.0.0-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@12.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65ba473e-6725-5b7a-87f7-cb9b6ccf17c6",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 12.0.0-tuxcare.4 of @angular/localize. not_affected \u2014 Angular 12.0.0 is not affected by CVE-2026-68945. The vulnerability concerns HttpTransferCache, a feature that caches HTTP requests during Server-Side Rendering (SSR) to reuse them during client-side hydration. This feature was first introduced in Angular 16.0.0 (#49509) and does not exist in Angular 12.0.0. The target version has no transfer_cache.ts implementation, no provideClientHydration A..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@12.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfff77b7-40de-555a-8890-0bd70eec0f20",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 12.0.0-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@12.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a922b75-8efe-561d-8e6c-6829ea815544",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 12.0.0-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@12.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7847a030-c921-5bd9-8144-fe5db04b6f87",
      "id": "CVE-2026-88056",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 12.0.0-tuxcare.4 of @angular/localize. not_affected \u2014 Angular 12.0.0 is not affected by CVE-2026-88056. The vulnerability pattern (String.prototype.trim() in URL resolution causing Unicode whitespace mismatch) was never present in this version. The original code used Node.js legacy url.parse() and WHATWG URL, neither of which strip Unicode whitespace, preventing the validation/resolution discrepancy described in the CVE. TuxCare's commit ae6a0227c..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@12.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44dfa24b-c8ec-59af-bc3b-98eee29597a7",
      "id": "CVE-2026-88057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 12.0.0-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@12.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c176611-aa84-56ec-baa3-e9475cfc842c",
      "id": "CVE-2026-88059",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 12.0.0-tuxcare.4 of @angular/localize. not_affected \u2014 Angular 12.0.0-tuxcare.4 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache, provideClientHydration(), and withRequestsMadeViaParent() \u2014 features that were first introduced in Angular 16.0.0 and are completely absent from Angular 12. The related CVE-2026-50170 patch file in this repository explicitly documents: \"the entire HttpTransferCache / provideClientHydration ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@12.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:822db3a8-e616-5f92-83fa-942fdeeea7ef",
      "id": "CVE-2026-88060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 12.0.0-tuxcare.4 of @angular/localize."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/localize@12.0.0-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/localize@12.0.0-tuxcare.4"
    }
  ]
}