{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fcd24a71-4bc0-5e0e-8b46-9c0d4abe1945",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/dompurify@3.1.6-tuxcare.5",
      "type": "library",
      "name": "dompurify",
      "version": "3.1.6-tuxcare.5",
      "purl": "pkg:npm/dompurify@3.1.6-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0320c27d-e772-59df-b714-c5b90f265d25",
      "id": "CVE-2025-15599",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-15599 is fixed in version 3.1.6-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2c26ed1-0df2-59b7-b89a-ab99f078adcb",
      "id": "CVE-2025-26791",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-26791 is fixed in version 3.1.6-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94f790a5-967d-56be-953d-5898b3e9a120",
      "id": "CVE-2026-0540",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-0540 is fixed in version 3.1.6-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a00605c-06ea-576d-80ee-80399a83f269",
      "id": "CVE-2026-41238",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41238 is fixed in version 3.1.6-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb74ef6a-e5f5-5f57-b162-0af6faefc283",
      "id": "CVE-2026-41239",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41239 is fixed in version 3.1.6-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b2de75d-6b6d-5dd1-b173-25c382918b3c",
      "id": "CVE-2026-41240",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41240 is fixed in version 3.1.6-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b30e1c93-9641-5a68-b9cb-1580908f161d",
      "id": "CVE-2026-49458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49458 affects version 3.1.6-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b71038d2-efd5-5637-808d-bf92e0db4279",
      "id": "CVE-2026-49459",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49459 is fixed in version 3.1.6-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75d8e80c-aa90-51c9-9932-d79ee4e06a18",
      "id": "CVE-2026-49978",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49978 is fixed in version 3.1.6-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:446d0429-9c90-59d7-bceb-c70bec501bef",
      "id": "CVE-2026-65898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65898 affects version 3.1.6-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f618d0b-2ea3-5c9f-a473-b3e25922802e",
      "id": "CVE-2026-65899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65899 affects version 3.1.6-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f98bed96-0d7c-5260-9bcd-9bc02da692e8",
      "id": "CVE-2026-65900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65900 affects version 3.1.6-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e820ac0b-f557-5da3-af6d-f184ec6d57bf",
      "id": "CVE-2026-65901",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65901 does not affect version 3.1.6-tuxcare.5 of dompurify. not_affected \u2014 Version 3.1.6 is not affected by CVE-2026-65901. The target contains a defensive mechanism that uses a realm-safe cached prototype getter (getNodeName) to validate element types, which bypasses attacker-controlled own properties set via Object.defineProperty. The CVE explicitly targets version 3.4.6, which is newer than the target version 3.1.6."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05dc4531-3388-5b74-9709-3dae57bd504c",
      "id": "CVE-2026-65902",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65902 affects version 3.1.6-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b0263df-5346-5276-8b5e-e99fbb909d8c",
      "id": "CVE-2026-65903",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65903 does not affect version 3.1.6-tuxcare.5 of dompurify. not_affected \u2014 Target version 3.1.6-tuxcare.5 does not contain the vulnerable code pattern described in CVE-2026-65903. The CVE describes a short-circuit evaluation issue in v3.3.3 where ADD_TAGS as a function (via EXTRA_ELEMENT_HANDLING.tagCheck) can bypass FORBID_TAGS. In v3.1.6, the equivalent logic (CUSTOM_ELEMENT_HANDLING.tagNameCheck) includes an explicit guard at line 1538 that checks !FORBID_TAGS[tagN..."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b840d517-d61c-5df7-b1cb-bcfd450e8c92",
      "id": "CVE-2026-65912",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65912 does not affect version 3.1.6-tuxcare.5 of dompurify. not_affected \u2014 DOMPurify version 3.1.6 is not affected by CVE-2026-65912. The vulnerability requires predicate-based attribute allowlisting features (ADD_ATTR as a predicate function or EXTRA_ELEMENT_HANDLING.attributeCheck) that do not exist in this version. Version 3.1.6 predates these features entirely."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f236dfb-867d-50e1-afc0-e96d3c704828",
      "id": "CVE-2026-65913",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65913 affects version 3.1.6-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5efcc4c-d149-5f56-b11b-a01a2b2fbe1b",
      "id": "CVE-2026-65914",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65914 does not affect version 3.1.6-tuxcare.5 of dompurify. not_affected \u2014 DOMPurify 3.1.6-tuxcare.5 is not affected by CVE-2026-65914. The target version contains a runtime defense mechanism (SAFE_FOR_XML, enabled by default) that removes attributes containing closing tags for special parsing-context elements (xmp, script, iframe, noembed, noframes, noscript). This defense prevents the mutation-XSS attack described in the CVE when DOMPurify is used with default confi..."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f5bcddc-f4fa-52af-a3d3-aa039b9efcc6",
      "id": "GHSA-39q2-94rc-95cp",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-39q2-94rc-95cp is fixed in version 3.1.6-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ced8f5d8-7f2d-5111-a6be-212c744e70d5",
      "id": "GHSA-76mc-f452-cxcm",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-76mc-f452-cxcm is fixed in version 3.1.6-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e9bf495-6104-5e26-998c-05344510b227",
      "id": "GHSA-c2j3-45gr-mqc4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-c2j3-45gr-mqc4 is fixed in version 3.1.6-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8e819dd-672c-51e7-95e1-40ac58d56898",
      "id": "GHSA-cj63-jhhr-wcxv",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cj63-jhhr-wcxv is fixed in version 3.1.6-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0dd3984-316a-5734-9a22-d641851d6b30",
      "id": "GHSA-cjmm-f4jc-qw8r",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cjmm-f4jc-qw8r is fixed in version 3.1.6-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:070b5730-1f38-5624-839a-ed1975bf3e7a",
      "id": "GHSA-cmwh-pvxp-8882",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cmwh-pvxp-8882 is fixed in version 3.1.6-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:719fc932-f753-5a22-99ea-56091b54d2c0",
      "id": "GHSA-gvmj-g25r-r7wr",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-gvmj-g25r-r7wr is fixed in version 3.1.6-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fbcf0c7-4e93-5716-80bb-c93c3745bd25",
      "id": "GHSA-h8r8-wccr-v5f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-h8r8-wccr-v5f2 is fixed in version 3.1.6-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9208361-93e9-5c74-a28f-bd3771529e01",
      "id": "GHSA-vxr8-fq34-vvx9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-vxr8-fq34-vvx9 is fixed in version 3.1.6-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbf797f3-34d0-5852-ae24-35d68ea54946",
      "id": "GHSA-x4vx-rjvf-j5p4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x4vx-rjvf-j5p4 is fixed in version 3.1.6-tuxcare.5 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/dompurify@3.1.6-tuxcare.5"
    }
  ]
}