{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4937265b-7a58-520d-bfa4-634d6b321f65",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1",
      "type": "library",
      "name": "DOMPurify",
      "version": "3.1.6-tuxcare.1",
      "purl": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:da7999bf-dac4-5a49-b2ff-7b6a32c8692a",
      "id": "CVE-2025-15599",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-15599 affects version 3.1.6-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cc24d6c-21c4-53f3-ae5a-49965dc4321a",
      "id": "CVE-2025-26791",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-26791 is fixed in version 3.1.6-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1310e4b9-c5a1-54cc-a3e9-d073db60cbf7",
      "id": "CVE-2026-0540",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-0540 affects version 3.1.6-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c013e022-4950-5ea7-b252-56930085a516",
      "id": "CVE-2026-41238",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41238 affects version 3.1.6-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a02826fc-9c91-5006-b74b-2c20d28bc41a",
      "id": "CVE-2026-41239",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41239 affects version 3.1.6-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20b2fd10-e584-5fc7-b539-7d014571bb25",
      "id": "CVE-2026-41240",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41240 affects version 3.1.6-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92bb87f3-1eaa-5852-8036-bc52e4119602",
      "id": "CVE-2026-49458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49458 affects version 3.1.6-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d60c9fa-b1e9-56f3-a7a5-ef81e7515522",
      "id": "CVE-2026-49459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49459 affects version 3.1.6-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5e874b2-e745-54cb-ad89-168e5fae1d58",
      "id": "CVE-2026-49978",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49978 affects version 3.1.6-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec05a0af-961b-5afc-9367-235bbefd8224",
      "id": "CVE-2026-65898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65898 affects version 3.1.6-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b82d9b3-9ddd-5e54-ba0d-355fc79aa16f",
      "id": "CVE-2026-65899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65899 affects version 3.1.6-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58369ce7-eb43-594a-bf7d-529e510d33e3",
      "id": "CVE-2026-65900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65900 affects version 3.1.6-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ba95ca3-5bc1-54db-b62f-1fcc4380fedc",
      "id": "CVE-2026-65901",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65901 does not affect version 3.1.6-tuxcare.1 of DOMPurify. not_affected \u2014 Version 3.1.6 is not affected by CVE-2026-65901. The target contains a defensive mechanism that uses a realm-safe cached prototype getter (getNodeName) to validate element types, which bypasses attacker-controlled own properties set via Object.defineProperty. The CVE explicitly targets version 3.4.6, which is newer than the target version 3.1.6."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2eef5e2a-e267-54f4-8903-7dff736626a0",
      "id": "CVE-2026-65902",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65902 affects version 3.1.6-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e19e55f-91ef-58cb-8be7-745cf992bc2c",
      "id": "CVE-2026-65903",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65903 does not affect version 3.1.6-tuxcare.1 of DOMPurify. not_affected \u2014 Target version 3.1.6-tuxcare.5 does not contain the vulnerable code pattern described in CVE-2026-65903. The CVE describes a short-circuit evaluation issue in v3.3.3 where ADD_TAGS as a function (via EXTRA_ELEMENT_HANDLING.tagCheck) can bypass FORBID_TAGS. In v3.1.6, the equivalent logic (CUSTOM_ELEMENT_HANDLING.tagNameCheck) includes an explicit guard at line 1538 that checks !FORBID_TAGS[tagN..."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d521df07-0520-5871-abf6-0d4d3d96decb",
      "id": "CVE-2026-65912",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65912 does not affect version 3.1.6-tuxcare.1 of DOMPurify. not_affected \u2014 DOMPurify version 3.1.6 is not affected by CVE-2026-65912. The vulnerability requires predicate-based attribute allowlisting features (ADD_ATTR as a predicate function or EXTRA_ELEMENT_HANDLING.attributeCheck) that do not exist in this version. Version 3.1.6 predates these features entirely."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bfd0404-75a1-5eec-b473-1e7b484fa8a3",
      "id": "CVE-2026-65913",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65913 affects version 3.1.6-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b99f2dfe-a82d-5e1b-9ef4-fd442e5ab441",
      "id": "CVE-2026-65914",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65914 does not affect version 3.1.6-tuxcare.1 of DOMPurify. not_affected \u2014 DOMPurify 3.1.6-tuxcare.5 is not affected by CVE-2026-65914. The target version contains a runtime defense mechanism (SAFE_FOR_XML, enabled by default) that removes attributes containing closing tags for special parsing-context elements (xmp, script, iframe, noembed, noframes, noscript). This defense prevents the mutation-XSS attack described in the CVE when DOMPurify is used with default confi..."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae749c35-e7bd-52d3-97ca-9be2bb5aae42",
      "id": "CVE-2026-66010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-66010 affects version 3.1.6-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fd36fdb-853d-5695-8dce-4625793f4765",
      "id": "CVE-2026-75838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-75838 affects version 3.1.6-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bfaa5ea-8099-5303-8e17-fcef747ca711",
      "id": "GHSA-39q2-94rc-95cp",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-39q2-94rc-95cp affects version 3.1.6-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ee7cd3b-bb27-55da-93e9-a4363b81408f",
      "id": "GHSA-55q2-fjhq-7xh7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-55q2-fjhq-7xh7 affects version 3.1.6-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2a56604-97b5-5dd9-8791-484ccda3e9b6",
      "id": "GHSA-76mc-f452-cxcm",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-76mc-f452-cxcm affects version 3.1.6-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a96f1ec-96be-5149-a334-db5d185e0fcb",
      "id": "GHSA-c2j3-45gr-mqc4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-c2j3-45gr-mqc4 affects version 3.1.6-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f86fb4cc-a7ae-59e7-846e-5fe537e09415",
      "id": "GHSA-cj63-jhhr-wcxv",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-cj63-jhhr-wcxv affects version 3.1.6-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b203004-206e-5cea-870f-77e928beea56",
      "id": "GHSA-cjmm-f4jc-qw8r",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-cjmm-f4jc-qw8r affects version 3.1.6-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02af13b8-3e88-51f9-b50d-cabba4c31ac9",
      "id": "GHSA-cmwh-pvxp-8882",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-cmwh-pvxp-8882 affects version 3.1.6-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82198237-fb87-5e9b-9088-b0e529ffc30a",
      "id": "GHSA-gvmj-g25r-r7wr",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-gvmj-g25r-r7wr affects version 3.1.6-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b02bf692-7041-579b-a39f-e21221704ebe",
      "id": "GHSA-h8r8-wccr-v5f2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-h8r8-wccr-v5f2 affects version 3.1.6-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3b4fbfd-a423-51a5-afdd-08d5cd44e85e",
      "id": "GHSA-vxr8-fq34-vvx9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-vxr8-fq34-vvx9 affects version 3.1.6-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81b1b3f3-3e96-532d-9b7e-94ec174d09f5",
      "id": "GHSA-x4vx-rjvf-j5p4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x4vx-rjvf-j5p4 affects version 3.1.6-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.1"
    }
  ]
}