{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fa306309-656b-55db-b716-89b9011b9db4",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3",
      "type": "library",
      "name": "DOMPurify",
      "version": "3.1.6-tuxcare.3",
      "purl": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:cd1cd7d3-3b62-56eb-8114-d82afffed01a",
      "id": "CVE-2025-15599",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-15599 is fixed in version 3.1.6-tuxcare.3 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79031079-c3e4-54ee-a597-88ec5d143b48",
      "id": "CVE-2025-26791",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-26791 is fixed in version 3.1.6-tuxcare.3 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcb8dc4e-9e3c-5802-83ef-42454418ba59",
      "id": "CVE-2026-0540",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-0540 is fixed in version 3.1.6-tuxcare.3 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0229ea41-f6cb-511c-a123-ba72b235f12f",
      "id": "CVE-2026-41238",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41238 is fixed in version 3.1.6-tuxcare.3 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c02ff19e-2d69-54d8-a9d8-05ebc6934b51",
      "id": "CVE-2026-41239",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41239 is fixed in version 3.1.6-tuxcare.3 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a64a5c6-4585-5472-8da8-37ab8a31e1dd",
      "id": "CVE-2026-41240",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41240 is fixed in version 3.1.6-tuxcare.3 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fa38a7b-8ebc-5eb3-8d16-7629fd2a5aec",
      "id": "CVE-2026-49458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49458 affects version 3.1.6-tuxcare.3 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35810cab-fc03-54e4-958b-fd1efa1bfab3",
      "id": "CVE-2026-49459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49459 affects version 3.1.6-tuxcare.3 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a05bd973-b1c1-56b1-a773-2fb011642863",
      "id": "CVE-2026-49978",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49978 affects version 3.1.6-tuxcare.3 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:230b8738-fc16-5354-a4a9-7c44b04dd7db",
      "id": "CVE-2026-65898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65898 affects version 3.1.6-tuxcare.3 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e619c799-1f16-548d-8937-432ab84b4765",
      "id": "CVE-2026-65899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65899 affects version 3.1.6-tuxcare.3 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f59b26c-c34f-54b1-b521-394665e0dfab",
      "id": "CVE-2026-65900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65900 affects version 3.1.6-tuxcare.3 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63578e66-d70f-5abb-bab5-8a499e4f71c4",
      "id": "CVE-2026-65901",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65901 does not affect version 3.1.6-tuxcare.3 of DOMPurify. not_affected \u2014 Version 3.1.6 is not affected by CVE-2026-65901. The target contains a defensive mechanism that uses a realm-safe cached prototype getter (getNodeName) to validate element types, which bypasses attacker-controlled own properties set via Object.defineProperty. The CVE explicitly targets version 3.4.6, which is newer than the target version 3.1.6."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7bb3c48-f8b4-5a3f-be40-884d259ade77",
      "id": "CVE-2026-65902",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65902 affects version 3.1.6-tuxcare.3 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1d6e420-d232-558f-8ac8-8fd287be4513",
      "id": "CVE-2026-65903",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65903 does not affect version 3.1.6-tuxcare.3 of DOMPurify. not_affected \u2014 Target version 3.1.6-tuxcare.5 does not contain the vulnerable code pattern described in CVE-2026-65903. The CVE describes a short-circuit evaluation issue in v3.3.3 where ADD_TAGS as a function (via EXTRA_ELEMENT_HANDLING.tagCheck) can bypass FORBID_TAGS. In v3.1.6, the equivalent logic (CUSTOM_ELEMENT_HANDLING.tagNameCheck) includes an explicit guard at line 1538 that checks !FORBID_TAGS[tagN..."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08c3294e-4aef-52fe-a005-93c6d872ede7",
      "id": "CVE-2026-65912",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65912 does not affect version 3.1.6-tuxcare.3 of DOMPurify. not_affected \u2014 DOMPurify version 3.1.6 is not affected by CVE-2026-65912. The vulnerability requires predicate-based attribute allowlisting features (ADD_ATTR as a predicate function or EXTRA_ELEMENT_HANDLING.attributeCheck) that do not exist in this version. Version 3.1.6 predates these features entirely."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10f0c801-f8d3-50f2-b215-2087079e1614",
      "id": "CVE-2026-65913",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65913 affects version 3.1.6-tuxcare.3 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed3ce7db-4ad8-5259-90ef-0c92244b67a4",
      "id": "CVE-2026-65914",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65914 does not affect version 3.1.6-tuxcare.3 of DOMPurify. not_affected \u2014 DOMPurify 3.1.6-tuxcare.5 is not affected by CVE-2026-65914. The target version contains a runtime defense mechanism (SAFE_FOR_XML, enabled by default) that removes attributes containing closing tags for special parsing-context elements (xmp, script, iframe, noembed, noframes, noscript). This defense prevents the mutation-XSS attack described in the CVE when DOMPurify is used with default confi..."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3e6ae04-9c8a-5f54-8fb1-007adb68d386",
      "id": "CVE-2026-66010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-66010 affects version 3.1.6-tuxcare.3 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb93b47e-e276-5a81-864d-ed73c980fe90",
      "id": "CVE-2026-75838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-75838 affects version 3.1.6-tuxcare.3 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d43ad74a-d680-53b3-9235-6e1e29ca73a6",
      "id": "GHSA-39q2-94rc-95cp",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-39q2-94rc-95cp is fixed in version 3.1.6-tuxcare.3 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be59eef2-9f22-5872-b257-0e1b15354274",
      "id": "GHSA-55q2-fjhq-7xh7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-55q2-fjhq-7xh7 affects version 3.1.6-tuxcare.3 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd7409d8-9b21-557d-8b26-304e962783b5",
      "id": "GHSA-76mc-f452-cxcm",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-76mc-f452-cxcm affects version 3.1.6-tuxcare.3 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08e5391d-c867-50f6-a5f9-730433280c7f",
      "id": "GHSA-c2j3-45gr-mqc4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-c2j3-45gr-mqc4 affects version 3.1.6-tuxcare.3 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7efbdb6-1b52-5325-a3f5-d7036e9085cd",
      "id": "GHSA-cj63-jhhr-wcxv",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cj63-jhhr-wcxv is fixed in version 3.1.6-tuxcare.3 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a82ebfc-3941-5af5-8cf4-33f229d8c5e6",
      "id": "GHSA-cjmm-f4jc-qw8r",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cjmm-f4jc-qw8r is fixed in version 3.1.6-tuxcare.3 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b907a2fe-3406-5513-be92-259e04737f15",
      "id": "GHSA-cmwh-pvxp-8882",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-cmwh-pvxp-8882 affects version 3.1.6-tuxcare.3 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81cd55dc-231c-524f-a7ad-9465750e7da8",
      "id": "GHSA-gvmj-g25r-r7wr",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-gvmj-g25r-r7wr affects version 3.1.6-tuxcare.3 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57b81ec8-876a-507d-a0c3-43f4da13c031",
      "id": "GHSA-h8r8-wccr-v5f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-h8r8-wccr-v5f2 is fixed in version 3.1.6-tuxcare.3 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7452d716-87b6-55c0-9e28-e07a9c35249d",
      "id": "GHSA-vxr8-fq34-vvx9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-vxr8-fq34-vvx9 affects version 3.1.6-tuxcare.3 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72744e8e-b2a6-5f85-afc1-b53233e31c47",
      "id": "GHSA-x4vx-rjvf-j5p4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x4vx-rjvf-j5p4 affects version 3.1.6-tuxcare.3 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.3"
    }
  ]
}