{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ee7f30a3-b1b1-5275-acd3-37bdc9c8b630",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2",
      "type": "library",
      "name": "DOMPurify",
      "version": "3.1.6-tuxcare.2",
      "purl": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:380a69c0-40ef-5e19-baed-b81181c15788",
      "id": "CVE-2025-15599",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-15599 is fixed in version 3.1.6-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63ea13ef-3d80-5b5b-be1b-0dbf707344ef",
      "id": "CVE-2025-26791",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-26791 is fixed in version 3.1.6-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9e6eef7-8dc0-5ab3-863a-0fb6ae6122bc",
      "id": "CVE-2026-0540",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-0540 is fixed in version 3.1.6-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59b6b159-7346-5959-b287-b75114da5468",
      "id": "CVE-2026-41238",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41238 affects version 3.1.6-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa1629d5-ca5d-5ce7-9b21-ab3546e9da89",
      "id": "CVE-2026-41239",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41239 affects version 3.1.6-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2fc5eff-80aa-5b0c-9663-276250e1cb5d",
      "id": "CVE-2026-41240",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41240 affects version 3.1.6-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b236236-1450-51c4-abd8-98180b9583b7",
      "id": "CVE-2026-49458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49458 affects version 3.1.6-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d0660b2-3e47-5e89-bed2-4cbf4c4c755f",
      "id": "CVE-2026-49459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49459 affects version 3.1.6-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d0e164f-0f72-5ab4-85a8-18a843ee1b43",
      "id": "CVE-2026-49978",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49978 affects version 3.1.6-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc5f1891-becb-5815-b222-6dfbdbb62c80",
      "id": "CVE-2026-65898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65898 affects version 3.1.6-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb9cd4e5-f7fd-5b60-8c20-4c2631cb39ea",
      "id": "CVE-2026-65899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65899 affects version 3.1.6-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d67e1fc-1095-53e0-bdfd-6580a5019ea3",
      "id": "CVE-2026-65900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65900 affects version 3.1.6-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d40e5f8e-fb9b-5151-8042-519a553e4017",
      "id": "CVE-2026-65901",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65901 does not affect version 3.1.6-tuxcare.2 of DOMPurify. not_affected \u2014 Version 3.1.6 is not affected by CVE-2026-65901. The target contains a defensive mechanism that uses a realm-safe cached prototype getter (getNodeName) to validate element types, which bypasses attacker-controlled own properties set via Object.defineProperty. The CVE explicitly targets version 3.4.6, which is newer than the target version 3.1.6."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4508fb13-57c1-52a8-9edb-4bed6f795190",
      "id": "CVE-2026-65902",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65902 affects version 3.1.6-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6a52c28-8f48-5d7b-8d69-7a5bb573ff6a",
      "id": "CVE-2026-65903",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65903 does not affect version 3.1.6-tuxcare.2 of DOMPurify. not_affected \u2014 Target version 3.1.6-tuxcare.5 does not contain the vulnerable code pattern described in CVE-2026-65903. The CVE describes a short-circuit evaluation issue in v3.3.3 where ADD_TAGS as a function (via EXTRA_ELEMENT_HANDLING.tagCheck) can bypass FORBID_TAGS. In v3.1.6, the equivalent logic (CUSTOM_ELEMENT_HANDLING.tagNameCheck) includes an explicit guard at line 1538 that checks !FORBID_TAGS[tagN..."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6bee88b-3144-5ec8-9a76-15f0c14cb123",
      "id": "CVE-2026-65912",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65912 does not affect version 3.1.6-tuxcare.2 of DOMPurify. not_affected \u2014 DOMPurify version 3.1.6 is not affected by CVE-2026-65912. The vulnerability requires predicate-based attribute allowlisting features (ADD_ATTR as a predicate function or EXTRA_ELEMENT_HANDLING.attributeCheck) that do not exist in this version. Version 3.1.6 predates these features entirely."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c31edc8f-6e4d-5a11-84a1-f895fd726763",
      "id": "CVE-2026-65913",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65913 affects version 3.1.6-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ff02abb-e8e9-50c1-bab2-2de2d9260c64",
      "id": "CVE-2026-65914",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65914 does not affect version 3.1.6-tuxcare.2 of DOMPurify. not_affected \u2014 DOMPurify 3.1.6-tuxcare.5 is not affected by CVE-2026-65914. The target version contains a runtime defense mechanism (SAFE_FOR_XML, enabled by default) that removes attributes containing closing tags for special parsing-context elements (xmp, script, iframe, noembed, noframes, noscript). This defense prevents the mutation-XSS attack described in the CVE when DOMPurify is used with default confi..."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:098ef6c5-da02-5f9c-84dc-eae894fbdf8e",
      "id": "CVE-2026-66010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-66010 affects version 3.1.6-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77ea14bc-ae27-5789-a849-89ef9bff71f1",
      "id": "CVE-2026-75838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-75838 affects version 3.1.6-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a441c0e0-40d4-5892-9009-01fb83ee3475",
      "id": "GHSA-39q2-94rc-95cp",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-39q2-94rc-95cp affects version 3.1.6-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67f6f1fb-adb1-5993-83d2-a130d5ce1eec",
      "id": "GHSA-55q2-fjhq-7xh7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-55q2-fjhq-7xh7 affects version 3.1.6-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a5c6cf8-4e5a-50eb-b059-3eddfc9b9105",
      "id": "GHSA-76mc-f452-cxcm",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-76mc-f452-cxcm affects version 3.1.6-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a646c35-538a-5715-bcc2-55e42451a6da",
      "id": "GHSA-c2j3-45gr-mqc4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-c2j3-45gr-mqc4 affects version 3.1.6-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27e1d0b0-c411-5e13-b8c3-07a4f5883042",
      "id": "GHSA-cj63-jhhr-wcxv",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-cj63-jhhr-wcxv affects version 3.1.6-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c002699-c00c-51a2-9c19-b3b91732b049",
      "id": "GHSA-cjmm-f4jc-qw8r",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-cjmm-f4jc-qw8r affects version 3.1.6-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9d5d75c-3180-556a-a95f-c83d2bc6b6bb",
      "id": "GHSA-cmwh-pvxp-8882",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-cmwh-pvxp-8882 affects version 3.1.6-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19314311-0ff7-5441-b787-7fb7ffee2a0f",
      "id": "GHSA-gvmj-g25r-r7wr",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-gvmj-g25r-r7wr affects version 3.1.6-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3538fd03-53d3-53bf-873d-9581e5dbbd51",
      "id": "GHSA-h8r8-wccr-v5f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-h8r8-wccr-v5f2 is fixed in version 3.1.6-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c0faf56-7dac-57a0-889c-f5224de33b0d",
      "id": "GHSA-vxr8-fq34-vvx9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-vxr8-fq34-vvx9 affects version 3.1.6-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9093f115-d25c-587c-a035-82052302c2af",
      "id": "GHSA-x4vx-rjvf-j5p4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x4vx-rjvf-j5p4 affects version 3.1.6-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.2"
    }
  ]
}