{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:cec84685-945b-5235-99c9-e6e171e48ba3",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/dompurify@2.3.0-tuxcare.1",
      "type": "library",
      "name": "dompurify",
      "version": "2.3.0-tuxcare.1",
      "purl": "pkg:npm/dompurify@2.3.0-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:4397b9c3-7205-5e90-b4da-37ec9e756971",
      "id": "CVE-2017-16115",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-16115 is fixed in version 2.3.0-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37693a32-9c57-542a-bf43-d55908c93663",
      "id": "CVE-2019-14862",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-14862 affects version 2.3.0-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a64bc3ad-c70f-5cc3-a2d5-04ae9a91d9b8",
      "id": "CVE-2020-26311",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-26311 is fixed in version 2.3.0-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:884fdb5e-2692-5589-8da5-68b545251ce7",
      "id": "CVE-2023-22467",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-22467 is fixed in version 2.3.0-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdf850a3-7ba4-5da7-ba99-cd145fa933ce",
      "id": "CVE-2024-45801",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45801 is fixed in version 2.3.0-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d428cedd-4555-5684-bc82-8bfa039aa552",
      "id": "CVE-2024-47875",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47875 is fixed in version 2.3.0-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b58609f3-f807-500d-b3ea-e5c691b1c0b8",
      "id": "CVE-2024-48910",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-48910 is fixed in version 2.3.0-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e2bceb0-b3fa-52dc-ae7e-4b2aa2f4e729",
      "id": "CVE-2025-26791",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-26791 is fixed in version 2.3.0-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e33ae8b-ebe5-5d34-ac8d-14cc818659db",
      "id": "CVE-2026-0540",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-0540 affects version 2.3.0-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f835195-0763-5358-b4f6-a8d58730a7c4",
      "id": "CVE-2026-41239",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41239 affects version 2.3.0-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae004e18-1109-56be-aed4-b55438842e02",
      "id": "CVE-2026-41240",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41240 affects version 2.3.0-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0bfb169-49ea-5430-a884-0e9c33019eba",
      "id": "CVE-2026-49458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49458 affects version 2.3.0-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87b78953-482e-5e70-b823-5824e18dbba8",
      "id": "CVE-2026-49459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49459 affects version 2.3.0-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12d85a54-8610-5866-80b2-92728bee608d",
      "id": "CVE-2026-49978",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49978 affects version 2.3.0-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bc4ae2b-916e-5f19-a640-50b5214cfc2f",
      "id": "CVE-2026-65898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65898 affects version 2.3.0-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5cd7b3f-7059-5044-9e01-4c8d4958a0fa",
      "id": "CVE-2026-65899",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65899 does not affect version 2.3.0-tuxcare.1 of dompurify. not_affected \u2014 Version 2.3.0 is not affected by CVE-2026-65899. The vulnerability requires the TRUSTED_TYPES_POLICY configuration option to inject a custom Trusted Types policy that survives clearConfig() calls. This configuration option does not exist in version 2.3.0\u2014it was introduced in version 3.0.3 (commit 8dc24e4, 335 commits later). In 2.3.0, trustedTypesPolicy is declared as a const created once at fa..."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efbb52c9-00a4-5c27-b1d4-d2d041bbd703",
      "id": "CVE-2026-65900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65900 affects version 2.3.0-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80e5173b-39f4-563a-8133-04142b3d6ece",
      "id": "CVE-2026-65901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65901 affects version 2.3.0-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1d27a63-cb85-5908-96eb-24b827610027",
      "id": "CVE-2026-65902",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65902 affects version 2.3.0-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ff8602b-8c47-5263-a8f2-b96a69ad7234",
      "id": "CVE-2026-65903",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65903 does not affect version 2.3.0-tuxcare.1 of dompurify. not_affected \u2014 CVE-2026-65903 describes a logic vulnerability in DOMPurify v3.3.3 where ADD_TAGS as a function callback (via EXTRA_ELEMENT_HANDLING.tagCheck) bypasses FORBID_TAGS due to short-circuit evaluation. The target version 2.3.0 is not affected because: (1) the EXTRA_ELEMENT_HANDLING and tagCheck callback mechanism does not exist in v2.3.0, (2) ADD_TAGS only accepts arrays/objects processed via addToS..."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2b2f8e0-4b9d-581d-a675-9d64b4813094",
      "id": "CVE-2026-65912",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65912 does not affect version 2.3.0-tuxcare.1 of dompurify. not_affected \u2014 The vulnerability described in CVE-2026-65912 does not exist in DOMPurify version 2.3.0-tuxcare.3. The vulnerable API (EXTRA_ELEMENT_HANDLING.attributeCheck) that accepts predicate functions for ADD_ATTR is not present in this version. In 2.3.0, ADD_ATTR only accepts arrays of attribute names and all attributes undergo full URI validation through _isValidAttribute, with no mechanism to short-ci..."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67f9c0be-2001-5615-8f41-0d7eeff7435e",
      "id": "CVE-2026-65913",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65913 affects version 2.3.0-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0aab0f2-dfd5-50d7-8952-be4333261283",
      "id": "CVE-2026-65914",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65914 affects version 2.3.0-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa41be95-9553-5c4e-914a-6d3d962c9e12",
      "id": "GHSA-39q2-94rc-95cp",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-39q2-94rc-95cp affects version 2.3.0-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09c06227-5cd0-5ffc-8fa1-3eff1e83b83f",
      "id": "GHSA-76mc-f452-cxcm",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-76mc-f452-cxcm affects version 2.3.0-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a14ea32f-2a60-50e5-a5b9-84926f2e03bb",
      "id": "GHSA-c2j3-45gr-mqc4",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-c2j3-45gr-mqc4 does not affect version 2.3.0-tuxcare.1 of dompurify. not_affected \u2014 DOMPurify version 2.3.0-tuxcare.2 is NOT affected by GHSA-c2j3-45gr-mqc4. The vulnerability requires the CUSTOM_ELEMENT_HANDLING configuration feature, which does not exist in version 2.3.0. This feature was introduced between versions 2.3.0 and 2.3.4 of the upstream codebase."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:910a98e3-cf52-54b9-9649-c3ff79f94dbc",
      "id": "GHSA-cj63-jhhr-wcxv",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-cj63-jhhr-wcxv affects version 2.3.0-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f99794c-dde6-5dc4-9a55-06b744da5d96",
      "id": "GHSA-cjmm-f4jc-qw8r",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-cjmm-f4jc-qw8r affects version 2.3.0-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97f0e78d-8155-5d51-a178-1935d05254a8",
      "id": "GHSA-cmwh-pvxp-8882",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-cmwh-pvxp-8882 affects version 2.3.0-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea95d538-eaca-587c-8915-12e7c73718cb",
      "id": "GHSA-gvmj-g25r-r7wr",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-gvmj-g25r-r7wr affects version 2.3.0-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:475de5b1-0fa8-5291-9d86-79bbac279cfb",
      "id": "GHSA-h8r8-wccr-v5f2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-h8r8-wccr-v5f2 affects version 2.3.0-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b50ef451-7bb5-5c20-80d1-a929822b4189",
      "id": "GHSA-vxr8-fq34-vvx9",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-vxr8-fq34-vvx9 does not affect version 2.3.0-tuxcare.1 of dompurify. not_affected \u2014 DOMPurify version 2.3.0-tuxcare.1 is not affected by GHSA-vxr8-fq34-vvx9 (Trusted Types policy persistence across clearConfig). The vulnerability requires the configurable TRUSTED_TYPES_POLICY feature, which was not introduced until version 3.0.3. In version 2.3.0, the trustedTypesPolicy is a const variable initialized once at module creation and cannot be overridden or configured by callers."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33ded31f-25b2-59c6-97a1-01c6610f7eda",
      "id": "GHSA-x4vx-rjvf-j5p4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x4vx-rjvf-j5p4 affects version 2.3.0-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/dompurify@2.3.0-tuxcare.1"
    }
  ]
}