{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8f0eff16-8ffe-5fd4-98a2-d3f9e1a996df",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/dompurify@2.5.8-tuxcare.1",
      "type": "library",
      "name": "dompurify",
      "version": "2.5.8-tuxcare.1",
      "purl": "pkg:npm/dompurify@2.5.8-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:74651d23-589f-56ad-91cd-5ff0626f6da1",
      "id": "CVE-2025-15599",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-15599 affects version 2.5.8-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7db396dd-5e21-50a0-b4a9-52d6f8dd33d7",
      "id": "CVE-2025-26791",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-26791 is fixed in version 2.5.8-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbd634be-2aba-5189-a8c4-191032679b92",
      "id": "CVE-2026-0540",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-0540 affects version 2.5.8-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebde4759-b319-53f7-9c2f-86f86dc06a9c",
      "id": "CVE-2026-41239",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41239 affects version 2.5.8-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa67a4db-0b34-5271-ae91-17949447277b",
      "id": "CVE-2026-41240",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41240 affects version 2.5.8-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec72a011-72d9-5b3f-95d4-c3f77694de36",
      "id": "CVE-2026-49458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49458 affects version 2.5.8-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3108aec1-f893-54ec-bd05-f1aad87c6d1b",
      "id": "CVE-2026-49459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49459 affects version 2.5.8-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60c8e931-d45c-59e1-8f1d-ae5f9f883a31",
      "id": "CVE-2026-49978",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49978 affects version 2.5.8-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48a49beb-7f51-57c0-9fd8-ce0231a88b39",
      "id": "CVE-2026-65898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65898 affects version 2.5.8-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a1658d6-e786-50e9-b956-f7cd96799c8e",
      "id": "CVE-2026-65899",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65899 does not affect version 2.5.8-tuxcare.1 of dompurify. not_affected \u2014 DOMPurify 2.5.8 is not affected by CVE-2026-65899. The vulnerability requires the TRUSTED_TYPES_POLICY configuration option to supply custom Trusted Types policies, which was introduced in version 3.0.3 (commit 8dc24e4, May 2023). Version 2.5.8 has no code path to accept this configuration and uses only a fixed, safe default policy created at module initialization."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94a95817-1851-5670-b71b-6aefd49242f1",
      "id": "CVE-2026-65900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65900 affects version 2.5.8-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38e1b086-c9c2-54ce-9852-4b45fdeebb99",
      "id": "CVE-2026-65901",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65901 does not affect version 2.5.8-tuxcare.1 of dompurify. not_affected \u2014 DOMPurify version 2.5.8-tuxcare.5 is NOT affected by CVE-2026-65901. The vulnerability described in the CVE affects version 3.4.6, where the code trusts currentNode.nodeName directly in IN_PLACE mode. However, version 2.5.8 already implements the suggested defense: it uses a cached trusted prototype getter (getNodeName) to read the real node name, preventing attackers from bypassing sanitizatio..."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:071de175-ccba-544a-9b28-b957a5ef5ac0",
      "id": "CVE-2026-65902",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65902 affects version 2.5.8-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44705797-f788-5a83-9017-a290862f9b7c",
      "id": "CVE-2026-65903",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65903 does not affect version 2.5.8-tuxcare.1 of dompurify. not_affected \u2014 CVE-2026-65903 describes a logic flaw in DOMPurify v3.3.3 where ADD_TAGS (as a function via EXTRA_ELEMENT_HANDLING.tagCheck) can bypass FORBID_TAGS due to short-circuit evaluation. The target repository at v2.5.8-tuxcare.5 uses a different architecture (CUSTOM_ELEMENT_HANDLING.tagNameCheck) and has an explicit guard (!FORBID_TAGS[tagName] at line 1278 of src/purify.js) that prevents custom elem..."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e969b596-e98f-5d64-9e63-d56015c4fba4",
      "id": "CVE-2026-65912",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65912 affects version 2.5.8-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ac367f7-e90d-5926-a2f3-c3c1c84ba6d1",
      "id": "CVE-2026-65913",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65913 affects version 2.5.8-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13dcd94b-18fd-5ec1-8d01-6ffc25f5e1ed",
      "id": "CVE-2026-65914",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65914 affects version 2.5.8-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16cad5e0-05af-5f3a-92ce-d0fd034f5af4",
      "id": "GHSA-39q2-94rc-95cp",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-39q2-94rc-95cp affects version 2.5.8-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c117584f-5125-55c1-ac6d-5c0846350bff",
      "id": "GHSA-76mc-f452-cxcm",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-76mc-f452-cxcm affects version 2.5.8-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8428ffe-a57c-5bdc-98c4-ae2a5b9c0211",
      "id": "GHSA-c2j3-45gr-mqc4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-c2j3-45gr-mqc4 affects version 2.5.8-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:438540bf-8170-50e8-8254-ac361cb886c1",
      "id": "GHSA-cj63-jhhr-wcxv",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-cj63-jhhr-wcxv affects version 2.5.8-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd4e845c-263f-5ec2-acdf-1231c6f8fd4a",
      "id": "GHSA-cjmm-f4jc-qw8r",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-cjmm-f4jc-qw8r affects version 2.5.8-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc2309b9-6802-56bf-9c74-b04bb1883b0f",
      "id": "GHSA-cmwh-pvxp-8882",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-cmwh-pvxp-8882 affects version 2.5.8-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e3c2715-803b-5529-9af2-8ea1f7385df1",
      "id": "GHSA-gvmj-g25r-r7wr",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-gvmj-g25r-r7wr affects version 2.5.8-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f07057c-a04e-5a94-8e72-f925f7f74413",
      "id": "GHSA-h8r8-wccr-v5f2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-h8r8-wccr-v5f2 affects version 2.5.8-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:085e1429-516b-5c6d-9e91-c4171f490785",
      "id": "GHSA-vxr8-fq34-vvx9",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-vxr8-fq34-vvx9 does not affect version 2.5.8-tuxcare.1 of dompurify. not_affected \u2014 DOMPurify 2.5.8-tuxcare.2 is not affected by GHSA-vxr8-fq34-vvx9. The vulnerability requires the TRUSTED_TYPES_POLICY configuration option, which does not exist in version 2.5.8. The target uses an immutable const trustedTypesPolicy initialized once at factory creation, making the attack vector (caller-supplied policy surviving clearConfig) impossible."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:086265ad-3b59-5d8f-9bf6-3bd914f980e9",
      "id": "GHSA-x4vx-rjvf-j5p4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x4vx-rjvf-j5p4 affects version 2.5.8-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.8-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/dompurify@2.5.8-tuxcare.1"
    }
  ]
}