{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5662c10e-f8ee-5ca3-86cb-28c07d175e35",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/dompurify@2.4.0-tuxcare.2",
      "type": "library",
      "name": "dompurify",
      "version": "2.4.0-tuxcare.2",
      "purl": "pkg:npm/dompurify@2.4.0-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7005cffa-b41a-50c5-9b70-327dac444475",
      "id": "CVE-2024-45801",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45801 is fixed in version 2.4.0-tuxcare.2 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ddc561cf-877c-501c-b555-42d97977fdc3",
      "id": "CVE-2024-47875",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47875 is fixed in version 2.4.0-tuxcare.2 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dae0538-bdab-5fce-a84d-06649f09b9f1",
      "id": "CVE-2024-48910",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-48910 is fixed in version 2.4.0-tuxcare.2 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47f2797c-000b-5e95-adf4-42a1f87747de",
      "id": "CVE-2025-26791",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-26791 is fixed in version 2.4.0-tuxcare.2 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcb138a3-0eb8-5cfe-a8c5-2b621aa6bdf6",
      "id": "CVE-2026-0540",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-0540 affects version 2.4.0-tuxcare.2 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74be7463-62b1-5d8f-9a68-d5610ad0e81a",
      "id": "CVE-2026-41239",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41239 is fixed in version 2.4.0-tuxcare.2 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48d48afa-6b97-5d40-8aa6-48855658c162",
      "id": "CVE-2026-41240",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41240 is fixed in version 2.4.0-tuxcare.2 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09b733d2-2f84-592d-96c6-7fc5f3fe5a90",
      "id": "CVE-2026-49458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49458 affects version 2.4.0-tuxcare.2 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:138f4de0-0aea-543d-a5e8-4dd35dea1b45",
      "id": "CVE-2026-49459",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-49459 does not affect version 2.4.0-tuxcare.2 of dompurify. already_fixed \u2014 The target (DOMPurify 2.4.0-tuxcare.1) is NOT vulnerable to CVE-2026-49459. While it lacks the vendor's realm-independent clobbering detection added in patches f6a7eb8/7996f1d/89da34e, the target has an alternative defense at the IN_PLACE entry point that prevents the attack. The defense at src/purify.js:1407-1416 rejects clobbered forms by throwing an error when dirty.nodeName stringifies to a..."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:643cf4b0-a15f-5431-bba8-1773238aa2bb",
      "id": "CVE-2026-49978",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49978 affects version 2.4.0-tuxcare.2 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:feaa464c-c636-51f2-9e9a-cde3e9fac46c",
      "id": "CVE-2026-6321",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6321 is fixed in version 2.4.0-tuxcare.2 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e05809f3-87aa-541b-8850-170066e65b81",
      "id": "CVE-2026-65898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65898 affects version 2.4.0-tuxcare.2 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa2ebc96-1643-5a1a-8867-bc13c4764374",
      "id": "CVE-2026-65899",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65899 does not affect version 2.4.0-tuxcare.2 of dompurify. not_affected \u2014 DOMPurify version 2.4.0 is not affected by CVE-2026-65899. The vulnerability requires the ability to configure a custom TRUSTED_TYPES_POLICY that can be retained across clearConfig() calls, but this configuration feature does not exist in version 2.4.0. The feature was added in later versions (3.0.3+) via commit bb04683. In version 2.4.0, trustedTypesPolicy is a const variable initialized once ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7254ca17-b0f0-50f4-8a8f-183257baebe9",
      "id": "CVE-2026-65900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65900 affects version 2.4.0-tuxcare.2 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9d63f27-f2f5-575c-9cb0-7a841d8cd197",
      "id": "CVE-2026-65901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65901 affects version 2.4.0-tuxcare.2 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0a95db6-f4ea-5d33-8e70-39b88c8f524e",
      "id": "CVE-2026-65902",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65902 affects version 2.4.0-tuxcare.2 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:953ef622-78c8-5eb7-a6ac-966e7cb53e1f",
      "id": "CVE-2026-65903",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65903 does not affect version 2.4.0-tuxcare.2 of dompurify. not_affected \u2014 DOMPurify v2.4.0 does not contain the CVE-2026-65903 vulnerability. The CVE targets v3.3.3's TypeScript implementation (src/purify.ts) where ADD_TAGS function bypasses FORBID_TAGS due to short-circuit evaluation. Version 2.4.0 uses a JavaScript implementation (src/purify.js) with a different, safer conditional structure that explicitly checks FORBID_TAGS before allowing custom element tagNameCh..."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cd5734f-543c-5c8c-9e24-d8e4a791f2bd",
      "id": "CVE-2026-65912",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65912 does not affect version 2.4.0-tuxcare.2 of dompurify. not_affected \u2014 DOMPurify 2.4.0 is not affected by CVE-2026-65912. The vulnerability requires function-predicate ADD_ATTR support via EXTRA_ELEMENT_HANDLING.attributeCheck, a feature that was introduced in versions between 2.4.0 and 3.3.1. Version 2.4.0 only supports ADD_ATTR as an array/set of attribute names and has no predicate evaluation path that could bypass URI validation. This assessment is confirmed b..."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adeb0dfc-4931-5fa7-9c42-d4fc59c9e6d2",
      "id": "CVE-2026-65913",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65913 affects version 2.4.0-tuxcare.2 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34f98eae-cacd-54a8-9201-d65406a18072",
      "id": "CVE-2026-65914",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65914 does not affect version 2.4.0-tuxcare.2 of dompurify. not_affected \u2014 DOMPurify 2.4.0 is a sanitization library with no own trust boundary. The CVE-2026-65914 mXSS vulnerability is an APPLICATION-LEVEL misuse pattern where applications wrap sanitized output in special HTML elements (<xmp>, <script>, etc.) and reparse via innerHTML. The library's sanitize() function correctly removes dangerous markup but has no code path that performs the re-contextualization oper..."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:643dd11b-28f0-54fe-af5b-7d8c63a7e3d4",
      "id": "GHSA-39q2-94rc-95cp",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-39q2-94rc-95cp is fixed in version 2.4.0-tuxcare.2 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f1b794f-3a4c-56c5-bb0e-7183470ca95a",
      "id": "GHSA-76mc-f452-cxcm",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-76mc-f452-cxcm affects version 2.4.0-tuxcare.2 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e99f7a75-a1e4-5299-9dfa-5c0b87fc9546",
      "id": "GHSA-c2j3-45gr-mqc4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-c2j3-45gr-mqc4 affects version 2.4.0-tuxcare.2 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:435f3cd5-4943-546d-88a7-2d91ef575786",
      "id": "GHSA-cj63-jhhr-wcxv",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cj63-jhhr-wcxv is fixed in version 2.4.0-tuxcare.2 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f939709a-f800-5a69-9844-bbc53fb29ea9",
      "id": "GHSA-cjmm-f4jc-qw8r",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cjmm-f4jc-qw8r is fixed in version 2.4.0-tuxcare.2 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fc85114-e896-5515-a287-9c0b9eecadda",
      "id": "GHSA-cmwh-pvxp-8882",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cmwh-pvxp-8882 is fixed in version 2.4.0-tuxcare.2 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:715c50d2-ed97-535a-b063-2082020af0ab",
      "id": "GHSA-gvmj-g25r-r7wr",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-gvmj-g25r-r7wr affects version 2.4.0-tuxcare.2 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9f1d73c-5a12-5cd7-8a99-e22148e72e90",
      "id": "GHSA-h8r8-wccr-v5f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-h8r8-wccr-v5f2 is fixed in version 2.4.0-tuxcare.2 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:970d75ad-59b9-57c5-b5d8-a04d69d12ed6",
      "id": "GHSA-vxr8-fq34-vvx9",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-vxr8-fq34-vvx9 does not affect version 2.4.0-tuxcare.2 of dompurify. not_affected \u2014 DOMPurify version 2.4.0 is not affected by GHSA-vxr8-fq34-vvx9. The vulnerability requires a TRUSTED_TYPES_POLICY configuration option that allows caller-supplied Trusted Types policies to persist across configuration boundaries. This feature was introduced in version 3.0.3 (May 2023), nine months after version 2.4.0 was released (August 2022). Version 2.4.0 uses only a hardcoded, immutable Tru..."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eeb620a2-a5d5-510c-bbe2-f5877fec3422",
      "id": "GHSA-x4vx-rjvf-j5p4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x4vx-rjvf-j5p4 affects version 2.4.0-tuxcare.2 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/dompurify@2.4.0-tuxcare.2"
    }
  ]
}