{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:949c792a-1782-56d0-bc39-6a8a599eab46",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/dompurify@2.5.9-tuxcare.5",
      "type": "library",
      "name": "dompurify",
      "version": "2.5.9-tuxcare.5",
      "purl": "pkg:npm/dompurify@2.5.9-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:82e8d0bf-a17b-5d8c-994b-2b01615517eb",
      "id": "CVE-2025-15599",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-15599 is fixed in version 2.5.9-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d026f43-2add-573a-a5d9-61c66142cd21",
      "id": "CVE-2025-26791",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-26791 affects version 2.5.9-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:450d6bf1-ebab-552e-95d7-c6557b3b6ff3",
      "id": "CVE-2026-0540",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-0540 affects version 2.5.9-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab095a22-d7e4-5c1b-b280-1a8d8e4daa47",
      "id": "CVE-2026-41239",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41239 affects version 2.5.9-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:167afaf8-9970-56b1-a44b-a2de3d35b487",
      "id": "CVE-2026-41240",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41240 affects version 2.5.9-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bab35cc-cb8f-5c04-94b5-b9798c1a7db5",
      "id": "CVE-2026-49458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49458 affects version 2.5.9-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0bec13a-f567-58d4-86a3-89abf0e648aa",
      "id": "CVE-2026-49459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49459 affects version 2.5.9-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37be137b-6112-53d1-b5c6-5716362d874a",
      "id": "CVE-2026-49978",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49978 affects version 2.5.9-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c5e32b7-cf3b-530b-b5c7-3b47eab63634",
      "id": "CVE-2026-65898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65898 affects version 2.5.9-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4258982-c345-5cf5-8d7e-725b5ac6eea2",
      "id": "CVE-2026-65899",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65899 does not affect version 2.5.9-tuxcare.5 of dompurify. not_affected \u2014 DOMPurify version 2.5.9 is not affected by CVE-2026-65899. The vulnerability requires the cfg.TRUSTED_TYPES_POLICY configuration option, which was introduced in version 3.0.0 (commit 8dc24e4, May 2023) and does not exist in the 2.5.x branch. In version 2.5.9, trustedTypesPolicy is a module-level constant initialized once at load time and cannot be overwritten through configuration, making the s..."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9451b23d-84a8-5070-9451-ade074b68f8d",
      "id": "CVE-2026-65900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65900 affects version 2.5.9-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f72a53d-d9d0-5449-b6b5-68a999f009dc",
      "id": "CVE-2026-65901",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65901 does not affect version 2.5.9-tuxcare.5 of dompurify. not_affected \u2014 Version 2.5.9 is NOT affected by CVE-2026-65901. The target has the cached prototype getter defense mechanism that prevents the attack where an attacker redefines the `nodeName` property on a malicious `<script>` element to bypass sanitization."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ea23bb7-3dd7-52eb-8251-76cfec7576c0",
      "id": "CVE-2026-65902",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65902 affects version 2.5.9-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21cf4521-a8eb-5e2c-b019-6399fe9f7de2",
      "id": "CVE-2026-65903",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65903 does not affect version 2.5.9-tuxcare.5 of dompurify. not_affected \u2014 v2.5.9 is not affected by CVE-2026-65903. The vulnerability requires EXTRA_ELEMENT_HANDLING.tagCheck functionality that was introduced after v2.5.9. The target version uses CUSTOM_ELEMENT_HANDLING.tagNameCheck with a different architecture that correctly enforces FORBID_TAGS precedence."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:558544bc-ea1d-574b-a7be-46baec93bc14",
      "id": "CVE-2026-65912",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65912 does not affect version 2.5.9-tuxcare.5 of dompurify. not_affected \u2014 CVE-2026-65912 describes a vulnerability where DOMPurify allows ADD_ATTR to be provided as a predicate function via EXTRA_ELEMENT_HANDLING.attributeCheck, bypassing URI validation for dangerous protocols like javascript:. Version 2.5.9-tuxcare.4 does not have this vulnerable feature. The EXTRA_ELEMENT_HANDLING configuration object does not exist in this version, and ADD_ATTR can only be an arra..."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9888e5ad-94cb-5a8b-875c-f5992aa05735",
      "id": "CVE-2026-65913",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65913 affects version 2.5.9-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:360161e6-5f11-5d4c-b78b-98c236a4ccbe",
      "id": "CVE-2026-65914",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65914 affects version 2.5.9-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e06fd32e-cd45-5d57-b3f9-c64fefcfc1db",
      "id": "GHSA-39q2-94rc-95cp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-39q2-94rc-95cp does not affect version 2.5.9-tuxcare.5 of dompurify. Version 2.5.9 is not vulnerable. Summary: The target repository (DOMPurify 2.5.9-tuxcare.2) does not contain the vulnerable feature. The CVE describes a logic bypass introduced when ADD_TAGS was enhanced to accept a function via EXTRA_ELEMENT_HANDLING.tagCheck. This feature was first introduced in commit 6c08b7d (2025-10-05) and appeared in version 3.3.3. The target version 2.5.9 predates this feature entirely. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54f6682d-148e-5da0-981d-64cac5b743f9",
      "id": "GHSA-76mc-f452-cxcm",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-76mc-f452-cxcm is fixed in version 2.5.9-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8fc4e01-b0ab-593e-800d-affdceb74419",
      "id": "GHSA-c2j3-45gr-mqc4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-c2j3-45gr-mqc4 is fixed in version 2.5.9-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc8bee2f-9a40-5d8f-b29c-150e51fecad1",
      "id": "GHSA-cj63-jhhr-wcxv",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-cj63-jhhr-wcxv affects version 2.5.9-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee1c2af4-2b8a-5f85-b7de-95e7c019fd28",
      "id": "GHSA-cjmm-f4jc-qw8r",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-cjmm-f4jc-qw8r affects version 2.5.9-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6e337c8-7052-582f-a916-11bf0392cb67",
      "id": "GHSA-cmwh-pvxp-8882",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cmwh-pvxp-8882 is fixed in version 2.5.9-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e295313-fcb4-53d2-92c5-c5125ba074bc",
      "id": "GHSA-gvmj-g25r-r7wr",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-gvmj-g25r-r7wr affects version 2.5.9-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed26561d-3866-5e6f-aeb7-6ac5c0b5d1d9",
      "id": "GHSA-h8r8-wccr-v5f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-h8r8-wccr-v5f2 is fixed in version 2.5.9-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1883b5c0-51ad-55fa-8c45-31bac20f35ea",
      "id": "GHSA-vxr8-fq34-vvx9",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-vxr8-fq34-vvx9 does not affect version 2.5.9-tuxcare.5 of dompurify. not_affected \u2014 Version 2.5.9 does not contain the vulnerability. The TRUSTED_TYPES_POLICY configuration option, which is required for exploitation, was not introduced until version 3.0.3. In version 2.5.9, trustedTypesPolicy is an immutable constant created once at initialization with no mechanism for external override."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:625e7010-e2e3-5aa1-a823-e20eb1140c1a",
      "id": "GHSA-x4vx-rjvf-j5p4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x4vx-rjvf-j5p4 is fixed in version 2.5.9-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@2.5.9-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/dompurify@2.5.9-tuxcare.5"
    }
  ]
}