{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:42497e1d-7674-51d3-8d78-473861d94668",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/dompurify@2.4.7-tuxcare.4",
      "type": "library",
      "name": "dompurify",
      "version": "2.4.7-tuxcare.4",
      "purl": "pkg:npm/dompurify@2.4.7-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:374a1cc5-6994-5cee-b49e-df8e28884797",
      "id": "CVE-2024-45801",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45801 is fixed in version 2.4.7-tuxcare.4 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26f9b490-3bbf-56c6-9c27-9a08f892bad8",
      "id": "CVE-2024-47875",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47875 is fixed in version 2.4.7-tuxcare.4 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f6793fc-fcf4-5a21-b1cd-849fdaf95172",
      "id": "CVE-2025-26791",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-26791 is fixed in version 2.4.7-tuxcare.4 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b42c0fa6-562b-57a1-afad-dba1d46c7e8c",
      "id": "CVE-2026-0540",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-0540 affects version 2.4.7-tuxcare.4 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7cb1db4-21bb-52c6-8892-a1af201ebe13",
      "id": "CVE-2026-41239",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41239 is fixed in version 2.4.7-tuxcare.4 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b4649f1-3987-5a63-b5c6-47df1b5a8002",
      "id": "CVE-2026-41240",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41240 is fixed in version 2.4.7-tuxcare.4 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05567285-524d-5b49-88a8-764fbdfe48fe",
      "id": "CVE-2026-49458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49458 affects version 2.4.7-tuxcare.4 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6557ad99-0ee4-589d-a224-dcd61bd7b306",
      "id": "CVE-2026-49459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49459 affects version 2.4.7-tuxcare.4 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82615760-d86f-5ac1-a732-7b8cb856bace",
      "id": "CVE-2026-49978",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49978 affects version 2.4.7-tuxcare.4 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8c195af-61a4-59c7-8e4c-fb2f2f286ac9",
      "id": "CVE-2026-65898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65898 affects version 2.4.7-tuxcare.4 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52f1b656-5514-5c9c-ba2b-4da9eb614960",
      "id": "CVE-2026-65899",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65899 does not affect version 2.4.7-tuxcare.4 of dompurify. not_affected \u2014 Version 2.4.7 is not affected by CVE-2026-65899. The vulnerability requires the TRUSTED_TYPES_POLICY configuration option, which was added in version 3.0.3 (commit 8dc24e4). Version 2.4.7 predates this feature and has no mechanism to set custom Trusted Types policies via configuration."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7758d84a-81bd-5931-a96d-06ef55251b75",
      "id": "CVE-2026-65900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65900 affects version 2.4.7-tuxcare.4 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:123b3cc3-9930-5a6f-90c1-c79e7debb821",
      "id": "CVE-2026-65901",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65901 does not affect version 2.4.7-tuxcare.4 of dompurify. not_affected \u2014 Version 2.4.7 is not affected by CVE-2026-65901. The target already implements the defense mechanism that the CVE describes as missing in version 3.4.6. Specifically, version 2.4.7 uses cached prototype getters (getNodeName) to access nodeName in the critical element decision path within _sanitizeElements, which bypasses instance property overrides. The CVE's attack vector relies on redefining ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abd9557d-f529-5f61-b6eb-4fc0879bc4de",
      "id": "CVE-2026-65902",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65902 affects version 2.4.7-tuxcare.4 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d96a2d5-f6ce-5538-9437-932a6494358c",
      "id": "CVE-2026-65903",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65903 does not affect version 2.4.7-tuxcare.4 of dompurify. not_affected \u2014 CVE-2026-65903 describes a vulnerability in DOMPurify v3.3.3 where FORBID_TAGS can be bypassed when ADD_TAGS is used as a function via EXTRA_ELEMENT_HANDLING.tagCheck. This feature does not exist in v2.4.7-tuxcare.3. The target version uses CUSTOM_ELEMENT_HANDLING instead, with different logic that correctly checks FORBID_TAGS before allowing custom elements through alternative mechanisms."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9cb7d8c9-a96c-52ae-925c-4c3eb6a4c577",
      "id": "CVE-2026-65912",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65912 does not affect version 2.4.7-tuxcare.4 of dompurify. not_affected \u2014 DOMPurify version 2.4.7 is not vulnerable to CVE-2026-65912. The vulnerability requires EXTRA_ELEMENT_HANDLING.attributeCheck predicate functionality that does not exist in this version. ADD_ATTR is only handled as an array, and URI validation always runs for href attributes, blocking javascript: URLs."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b719ccf-9158-55df-8ff2-e478134304f0",
      "id": "CVE-2026-65913",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65913 affects version 2.4.7-tuxcare.4 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cf02af8-3817-54e0-9228-ff0442dd901c",
      "id": "CVE-2026-65914",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65914 does not affect version 2.4.7-tuxcare.4 of dompurify. not_affected \u2014 CVE-2026-65914 describes a mutation-XSS (mXSS) via re-contextualization that occurs when an APPLICATION wraps DOMPurify's sanitized output in special HTML elements (xmp, script, noscript, iframe, noembed, noframes) and re-parses it with innerHTML. DOMPurify 2.4.7 is NOT affected because the vulnerability requires application-level operations outside DOMPurify's control and explicitly warned aga..."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cad2c7c1-d429-5d72-993c-fb53f10e1537",
      "id": "GHSA-39q2-94rc-95cp",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-39q2-94rc-95cp is fixed in version 2.4.7-tuxcare.4 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b0acba0-2669-5272-9a01-57285ad301c1",
      "id": "GHSA-76mc-f452-cxcm",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-76mc-f452-cxcm is fixed in version 2.4.7-tuxcare.4 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18d9ce71-02f3-52b1-8cc5-a91d066f55c8",
      "id": "GHSA-c2j3-45gr-mqc4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-c2j3-45gr-mqc4 is fixed in version 2.4.7-tuxcare.4 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18763d11-e1fd-5ee2-9a05-13a1f81808aa",
      "id": "GHSA-cj63-jhhr-wcxv",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cj63-jhhr-wcxv is fixed in version 2.4.7-tuxcare.4 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3bc9156-3d4b-5bbf-b49e-256388ceb787",
      "id": "GHSA-cjmm-f4jc-qw8r",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cjmm-f4jc-qw8r is fixed in version 2.4.7-tuxcare.4 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2609fafe-d787-5826-854d-2868ee2a9a6f",
      "id": "GHSA-cmwh-pvxp-8882",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cmwh-pvxp-8882 is fixed in version 2.4.7-tuxcare.4 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:253d4f10-de51-5e4b-a204-f0441406dbcd",
      "id": "GHSA-gvmj-g25r-r7wr",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-gvmj-g25r-r7wr affects version 2.4.7-tuxcare.4 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ade3a32-df66-5ad6-a2b4-18043af16aff",
      "id": "GHSA-h8r8-wccr-v5f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-h8r8-wccr-v5f2 is fixed in version 2.4.7-tuxcare.4 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7d82e13-e174-51ff-802d-7fd03004c825",
      "id": "GHSA-vxr8-fq34-vvx9",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-vxr8-fq34-vvx9 does not affect version 2.4.7-tuxcare.4 of dompurify. not_affected \u2014 DOMPurify version 2.4.7 does not have the TRUSTED_TYPES_POLICY configuration option that is required for this vulnerability. The vulnerable feature (configurable Trusted Types policy) was introduced in version 3.0.3 (May 2023), while the target is version 2.4.7 which predates this feature."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91f46237-f743-5fe2-8a81-16cf9c69f105",
      "id": "GHSA-x4vx-rjvf-j5p4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x4vx-rjvf-j5p4 is fixed in version 2.4.7-tuxcare.4 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.4.7-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/dompurify@2.4.7-tuxcare.4"
    }
  ]
}