{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:bdb7cdc9-51fc-5210-9728-c71f9b73d690",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/dompurify@2.4.3-tuxcare.6",
      "type": "library",
      "name": "dompurify",
      "version": "2.4.3-tuxcare.6",
      "purl": "pkg:npm/dompurify@2.4.3-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f3bb7a1a-5b3f-5598-aefa-69dac2a30241",
      "id": "CVE-2023-26136",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26136 is fixed in version 2.4.3-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3a3b040-a32e-5a03-8422-1a9d43a63b14",
      "id": "CVE-2024-45801",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45801 is fixed in version 2.4.3-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4712a777-17d2-56d0-bd0e-c00a7858e1c7",
      "id": "CVE-2024-47875",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47875 is fixed in version 2.4.3-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2434fd59-8372-5174-b145-25ce58accbca",
      "id": "CVE-2025-26791",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-26791 is fixed in version 2.4.3-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb4773d2-934b-503d-a55b-7079520c7b20",
      "id": "CVE-2026-0540",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-0540 affects version 2.4.3-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f63e9c52-1806-58fa-a226-b26521396e87",
      "id": "CVE-2026-41239",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41239 affects version 2.4.3-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b024a6f-93d7-5097-b027-d8057ea87805",
      "id": "CVE-2026-41240",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41240 affects version 2.4.3-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa4d754f-0e4f-5dca-91da-536f6b55ed91",
      "id": "CVE-2026-49458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49458 affects version 2.4.3-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41868bb9-f372-5b11-98d3-1b67cb308bb6",
      "id": "CVE-2026-49459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49459 affects version 2.4.3-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1eae9191-b465-56fc-8a04-cacdc1e8e648",
      "id": "CVE-2026-49978",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49978 affects version 2.4.3-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2b9f392-e08d-5e64-b88d-53bbc5485230",
      "id": "CVE-2026-65898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65898 affects version 2.4.3-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ddf34e1-c91f-500e-8e15-5f63c969a996",
      "id": "CVE-2026-65899",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65899 does not affect version 2.4.3-tuxcare.6 of dompurify. not_affected \u2014 DOMPurify version 2.4.3-tuxcare.5 is not affected by CVE-2026-65899. The vulnerability requires the TRUSTED_TYPES_POLICY configuration feature, which does not exist in version 2.4.3. This feature was introduced in version 3.0.x (commit 8dc24e4, May 2023), well after the 2.4.3 release. Without the ability to supply a custom Trusted Types policy via configuration, the state contamination describe..."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3519b821-e9e2-54b0-80dd-96877af6aad1",
      "id": "CVE-2026-65900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65900 affects version 2.4.3-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94c7ec57-5936-578a-80ed-243a1074cd04",
      "id": "CVE-2026-65901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65901 affects version 2.4.3-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:323e3ef7-3a25-5f36-b4ab-074cdcced359",
      "id": "CVE-2026-65902",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65902 affects version 2.4.3-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e8282a4-4eec-5044-8617-06ee0da3cf05",
      "id": "CVE-2026-65903",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65903 does not affect version 2.4.3-tuxcare.6 of dompurify. not_affected \u2014 The vulnerability described in CVE-2026-65903 does not affect DOMPurify v2.4.3. The CVE describes a logic inconsistency in v3.3.3 where ADD_TAGS used as a function (via EXTRA_ELEMENT_HANDLING.tagCheck) can bypass FORBID_TAGS due to short-circuit evaluation. This mechanism does not exist in v2.4.3, which uses a fundamentally different architecture that prevents this bypass pattern."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4784a159-a9e0-5463-b86c-6e8ca57f41c7",
      "id": "CVE-2026-65912",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65912 is fixed in version 2.4.3-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79326039-df47-59f2-a392-ebb590c862e1",
      "id": "CVE-2026-65913",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65913 affects version 2.4.3-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95228ba5-33e0-5134-b89a-f4db19ff241a",
      "id": "CVE-2026-65914",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65914 affects version 2.4.3-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4e25fc5-11bc-5ccf-9b9b-3837251ce0b7",
      "id": "GHSA-39q2-94rc-95cp",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-39q2-94rc-95cp is fixed in version 2.4.3-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9242c97-ac90-5525-ac45-adfd99999f1f",
      "id": "GHSA-76mc-f452-cxcm",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-76mc-f452-cxcm affects version 2.4.3-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:630555f7-dc48-5fcd-8f99-9470191dbf0c",
      "id": "GHSA-c2j3-45gr-mqc4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-c2j3-45gr-mqc4 affects version 2.4.3-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f29daa94-8a00-56ec-abe2-ca235fd02256",
      "id": "GHSA-cj63-jhhr-wcxv",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-cj63-jhhr-wcxv affects version 2.4.3-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04f9fb61-d04c-5cce-bbb4-1e7fdf4db26c",
      "id": "GHSA-cjmm-f4jc-qw8r",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-cjmm-f4jc-qw8r affects version 2.4.3-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3598e3e1-653d-5750-a50d-74521523851c",
      "id": "GHSA-cmwh-pvxp-8882",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cmwh-pvxp-8882 is fixed in version 2.4.3-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d00fd0c7-bc49-51ae-b537-f655e76b7335",
      "id": "GHSA-gvmj-g25r-r7wr",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-gvmj-g25r-r7wr affects version 2.4.3-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3eab18ed-3aca-5e22-bb6d-e4d0f6c93509",
      "id": "GHSA-h8r8-wccr-v5f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-h8r8-wccr-v5f2 is fixed in version 2.4.3-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:122cd94e-a474-5228-814d-c2427da9d131",
      "id": "GHSA-vxr8-fq34-vvx9",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-vxr8-fq34-vvx9 does not affect version 2.4.3-tuxcare.6 of dompurify. not_affected \u2014 DOMPurify version 2.4.3-tuxcare.1 is not affected by GHSA-vxr8-fq34-vvx9. The vulnerability requires the TRUSTED_TYPES_POLICY configuration option, which was introduced in version 3.0.3. Version 2.4.3 does not have this feature and therefore cannot exhibit the vulnerable behavior where a caller-supplied Trusted Types policy persists after clearConfig()."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73fa51cd-e4aa-5d00-9798-e685408ae72e",
      "id": "GHSA-x4vx-rjvf-j5p4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x4vx-rjvf-j5p4 is fixed in version 2.4.3-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.3-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/dompurify@2.4.3-tuxcare.6"
    }
  ]
}