{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ef1851c2-02de-5eda-b2e8-4889ec353edb",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/dompurify@3.1.6-tuxcare.6",
      "type": "library",
      "name": "dompurify",
      "version": "3.1.6-tuxcare.6",
      "purl": "pkg:npm/dompurify@3.1.6-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:3b5fcbf2-a021-5bfb-a821-687c0469eceb",
      "id": "CVE-2025-15599",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-15599 is fixed in version 3.1.6-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:979e1b92-d0af-5f9f-8eb6-dba3739fb8b5",
      "id": "CVE-2025-26791",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-26791 is fixed in version 3.1.6-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5a986a8-de3d-5157-a3f0-a06e88900f81",
      "id": "CVE-2026-0540",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-0540 is fixed in version 3.1.6-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b581c6cc-2dac-59cb-bd82-b7d95bf1b489",
      "id": "CVE-2026-41238",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41238 is fixed in version 3.1.6-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:566037be-e90a-5b34-87e4-61865b111d19",
      "id": "CVE-2026-41239",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41239 is fixed in version 3.1.6-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e62d5f62-4a27-5059-83e6-4c147f1bdb66",
      "id": "CVE-2026-41240",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41240 is fixed in version 3.1.6-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1eeb7357-4f0d-5243-853a-342f23edc338",
      "id": "CVE-2026-49458",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49458 is fixed in version 3.1.6-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0fcf576-9623-55f0-8a21-3424c198e507",
      "id": "CVE-2026-49459",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49459 is fixed in version 3.1.6-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2295d8a2-5d45-5f10-94c3-d58ef44f3544",
      "id": "CVE-2026-49978",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49978 is fixed in version 3.1.6-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02b1bb5e-f7eb-5ea3-b128-acd049a12fba",
      "id": "CVE-2026-65898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65898 affects version 3.1.6-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bfe1cd9-123e-5222-b8a1-28115caa9a7e",
      "id": "CVE-2026-65899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65899 affects version 3.1.6-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72e4e242-9109-55a6-beb2-dcc022a2391f",
      "id": "CVE-2026-65900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65900 affects version 3.1.6-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fea89cd7-1d63-55b3-b189-dfb523dfe362",
      "id": "CVE-2026-65901",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65901 does not affect version 3.1.6-tuxcare.6 of dompurify. not_affected \u2014 Version 3.1.6 is not affected by CVE-2026-65901. The target contains a defensive mechanism that uses a realm-safe cached prototype getter (getNodeName) to validate element types, which bypasses attacker-controlled own properties set via Object.defineProperty. The CVE explicitly targets version 3.4.6, which is newer than the target version 3.1.6."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6c96b0a-a4dd-50eb-beba-51bf9099e452",
      "id": "CVE-2026-65902",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65902 affects version 3.1.6-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7074e429-0051-5913-a275-e6ec4e75bbea",
      "id": "CVE-2026-65903",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65903 does not affect version 3.1.6-tuxcare.6 of dompurify. not_affected \u2014 Target version 3.1.6-tuxcare.5 does not contain the vulnerable code pattern described in CVE-2026-65903. The CVE describes a short-circuit evaluation issue in v3.3.3 where ADD_TAGS as a function (via EXTRA_ELEMENT_HANDLING.tagCheck) can bypass FORBID_TAGS. In v3.1.6, the equivalent logic (CUSTOM_ELEMENT_HANDLING.tagNameCheck) includes an explicit guard at line 1538 that checks !FORBID_TAGS[tagN..."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19caf9c3-d533-5e4d-a8d7-8b6358e29d06",
      "id": "CVE-2026-65912",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65912 does not affect version 3.1.6-tuxcare.6 of dompurify. not_affected \u2014 DOMPurify version 3.1.6 is not affected by CVE-2026-65912. The vulnerability requires predicate-based attribute allowlisting features (ADD_ATTR as a predicate function or EXTRA_ELEMENT_HANDLING.attributeCheck) that do not exist in this version. Version 3.1.6 predates these features entirely."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afa199fc-80fc-5f45-8ff7-25962fbcfb8f",
      "id": "CVE-2026-65913",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65913 affects version 3.1.6-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33c81589-32a0-5b89-b46f-6deb1401043e",
      "id": "CVE-2026-65914",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65914 does not affect version 3.1.6-tuxcare.6 of dompurify. not_affected \u2014 DOMPurify 3.1.6-tuxcare.5 is not affected by CVE-2026-65914. The target version contains a runtime defense mechanism (SAFE_FOR_XML, enabled by default) that removes attributes containing closing tags for special parsing-context elements (xmp, script, iframe, noembed, noframes, noscript). This defense prevents the mutation-XSS attack described in the CVE when DOMPurify is used with default confi..."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8207aae2-fc2f-5994-a466-2655983dbf2a",
      "id": "GHSA-39q2-94rc-95cp",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-39q2-94rc-95cp is fixed in version 3.1.6-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9803840e-e601-51dd-8713-9ce53b7c578f",
      "id": "GHSA-55q2-fjhq-7xh7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-55q2-fjhq-7xh7 affects version 3.1.6-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e398a9e-e0ef-565d-9657-cde47f8c6479",
      "id": "GHSA-76mc-f452-cxcm",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-76mc-f452-cxcm is fixed in version 3.1.6-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8ef7e69-8419-5535-ba75-1d2a7d175a98",
      "id": "GHSA-c2j3-45gr-mqc4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-c2j3-45gr-mqc4 is fixed in version 3.1.6-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5c2480a-7c3a-58fa-b8b5-5e1fc44d3c10",
      "id": "GHSA-cj63-jhhr-wcxv",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cj63-jhhr-wcxv is fixed in version 3.1.6-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:667d0064-672a-5902-9a73-f5c96ee0ef73",
      "id": "GHSA-cjmm-f4jc-qw8r",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cjmm-f4jc-qw8r is fixed in version 3.1.6-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d79b5f38-807e-5809-9778-d58421875dea",
      "id": "GHSA-cmwh-pvxp-8882",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cmwh-pvxp-8882 is fixed in version 3.1.6-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbd43921-f1b6-56bc-ac80-6b313c5bca6b",
      "id": "GHSA-gvmj-g25r-r7wr",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-gvmj-g25r-r7wr is fixed in version 3.1.6-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c786726-5f20-59aa-a3b6-1aac96585981",
      "id": "GHSA-h8r8-wccr-v5f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-h8r8-wccr-v5f2 is fixed in version 3.1.6-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50c2f083-6663-5cc7-b4f1-b347951000a8",
      "id": "GHSA-vxr8-fq34-vvx9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-vxr8-fq34-vvx9 is fixed in version 3.1.6-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fb9ea59-ad5e-50e4-a16a-c5cc1f7a54ca",
      "id": "GHSA-x4vx-rjvf-j5p4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x4vx-rjvf-j5p4 is fixed in version 3.1.6-tuxcare.6 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/dompurify@3.1.6-tuxcare.6"
    }
  ]
}