{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8f578b7b-fbab-5747-8f9e-654ec23f889d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6",
      "type": "library",
      "name": "DOMPurify",
      "version": "3.1.6-tuxcare.6",
      "purl": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:5e103928-519e-5c8a-bb0e-40b735ab14fa",
      "id": "CVE-2025-15599",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-15599 is fixed in version 3.1.6-tuxcare.6 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c51ac841-3044-5eb3-8159-158c5747cc21",
      "id": "CVE-2025-26791",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-26791 is fixed in version 3.1.6-tuxcare.6 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5ec516b-482b-580e-9422-1041187e7a21",
      "id": "CVE-2026-0540",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-0540 is fixed in version 3.1.6-tuxcare.6 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afc24374-3390-5bc3-ad40-1184abf838d1",
      "id": "CVE-2026-41238",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41238 is fixed in version 3.1.6-tuxcare.6 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d8b084f-998f-52fd-bd69-bed149c4b5e5",
      "id": "CVE-2026-41239",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41239 is fixed in version 3.1.6-tuxcare.6 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7203896e-039e-5c6d-85f3-95eb338572ae",
      "id": "CVE-2026-41240",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41240 is fixed in version 3.1.6-tuxcare.6 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef1ee813-8de5-5bfa-b159-59ec7b78f0e9",
      "id": "CVE-2026-49458",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49458 is fixed in version 3.1.6-tuxcare.6 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18d9da26-ccbd-500e-a1cb-6a668185988f",
      "id": "CVE-2026-49459",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49459 is fixed in version 3.1.6-tuxcare.6 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33c19139-c7dd-5150-a4d1-9de5ef0c7b7f",
      "id": "CVE-2026-49978",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49978 is fixed in version 3.1.6-tuxcare.6 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3306fb4b-a513-55fe-941c-5223b2c0eea3",
      "id": "CVE-2026-65898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65898 affects version 3.1.6-tuxcare.6 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa539616-fba7-517a-81e5-7bc63bede80b",
      "id": "CVE-2026-65899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65899 affects version 3.1.6-tuxcare.6 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5725aed-ec85-5a7e-9795-dc570acf9711",
      "id": "CVE-2026-65900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65900 affects version 3.1.6-tuxcare.6 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e5f04cb-0e0f-5977-a688-dc6c12945590",
      "id": "CVE-2026-65901",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65901 does not affect version 3.1.6-tuxcare.6 of DOMPurify. not_affected \u2014 Version 3.1.6 is not affected by CVE-2026-65901. The target contains a defensive mechanism that uses a realm-safe cached prototype getter (getNodeName) to validate element types, which bypasses attacker-controlled own properties set via Object.defineProperty. The CVE explicitly targets version 3.4.6, which is newer than the target version 3.1.6."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33aa5d23-6cda-5371-a590-664c34a5dfdc",
      "id": "CVE-2026-65902",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65902 affects version 3.1.6-tuxcare.6 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8c21c8f-fda8-5f74-8e09-c725f3085c54",
      "id": "CVE-2026-65903",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65903 does not affect version 3.1.6-tuxcare.6 of DOMPurify. not_affected \u2014 Target version 3.1.6-tuxcare.5 does not contain the vulnerable code pattern described in CVE-2026-65903. The CVE describes a short-circuit evaluation issue in v3.3.3 where ADD_TAGS as a function (via EXTRA_ELEMENT_HANDLING.tagCheck) can bypass FORBID_TAGS. In v3.1.6, the equivalent logic (CUSTOM_ELEMENT_HANDLING.tagNameCheck) includes an explicit guard at line 1538 that checks !FORBID_TAGS[tagN..."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e752175e-16fc-5e51-b207-93fa0f265cb5",
      "id": "CVE-2026-65912",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65912 does not affect version 3.1.6-tuxcare.6 of DOMPurify. not_affected \u2014 DOMPurify version 3.1.6 is not affected by CVE-2026-65912. The vulnerability requires predicate-based attribute allowlisting features (ADD_ATTR as a predicate function or EXTRA_ELEMENT_HANDLING.attributeCheck) that do not exist in this version. Version 3.1.6 predates these features entirely."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb8b1c09-dd16-5672-9480-461af36cde11",
      "id": "CVE-2026-65913",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65913 affects version 3.1.6-tuxcare.6 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:beb13cf5-bf54-5550-b443-a876079486d3",
      "id": "CVE-2026-65914",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65914 does not affect version 3.1.6-tuxcare.6 of DOMPurify. not_affected \u2014 DOMPurify 3.1.6-tuxcare.5 is not affected by CVE-2026-65914. The target version contains a runtime defense mechanism (SAFE_FOR_XML, enabled by default) that removes attributes containing closing tags for special parsing-context elements (xmp, script, iframe, noembed, noframes, noscript). This defense prevents the mutation-XSS attack described in the CVE when DOMPurify is used with default confi..."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3a8f463-d8af-5db2-87e9-3b30fb9f345b",
      "id": "CVE-2026-66010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-66010 affects version 3.1.6-tuxcare.6 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6590105-477e-599f-a5d6-cd90ec09fab4",
      "id": "CVE-2026-75838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-75838 affects version 3.1.6-tuxcare.6 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:627a0372-0f7b-545e-bc68-edf005aa602a",
      "id": "GHSA-39q2-94rc-95cp",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-39q2-94rc-95cp is fixed in version 3.1.6-tuxcare.6 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:028adc4a-f999-554d-8df9-38a1fb535db6",
      "id": "GHSA-55q2-fjhq-7xh7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-55q2-fjhq-7xh7 affects version 3.1.6-tuxcare.6 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a39eb74-473a-581b-8dd4-776bfa9fa880",
      "id": "GHSA-76mc-f452-cxcm",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-76mc-f452-cxcm is fixed in version 3.1.6-tuxcare.6 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66d8c683-1a2c-57c4-ad37-e10ce3843232",
      "id": "GHSA-c2j3-45gr-mqc4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-c2j3-45gr-mqc4 is fixed in version 3.1.6-tuxcare.6 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:285869b7-0386-5785-b275-008c44419406",
      "id": "GHSA-cj63-jhhr-wcxv",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cj63-jhhr-wcxv is fixed in version 3.1.6-tuxcare.6 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bf4f278-fd56-5ba2-9514-6ba835e91270",
      "id": "GHSA-cjmm-f4jc-qw8r",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cjmm-f4jc-qw8r is fixed in version 3.1.6-tuxcare.6 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8162140-b4b3-5aef-bb25-05a56f0d6bcd",
      "id": "GHSA-cmwh-pvxp-8882",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cmwh-pvxp-8882 is fixed in version 3.1.6-tuxcare.6 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b97e0788-5f23-5b20-93f8-4679e3f7d327",
      "id": "GHSA-gvmj-g25r-r7wr",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-gvmj-g25r-r7wr is fixed in version 3.1.6-tuxcare.6 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28c6a420-2321-576b-86c5-317c068aa7eb",
      "id": "GHSA-h8r8-wccr-v5f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-h8r8-wccr-v5f2 is fixed in version 3.1.6-tuxcare.6 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bd981d1-de7b-5270-ae82-d4585055dfc9",
      "id": "GHSA-vxr8-fq34-vvx9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-vxr8-fq34-vvx9 is fixed in version 3.1.6-tuxcare.6 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41874649-8500-5c95-9611-b231e0254866",
      "id": "GHSA-x4vx-rjvf-j5p4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x4vx-rjvf-j5p4 is fixed in version 3.1.6-tuxcare.6 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.6"
    }
  ]
}