{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9675b602-adb4-5b09-b934-9db5bb60acca",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7",
      "type": "library",
      "name": "DOMPurify",
      "version": "3.1.6-tuxcare.7",
      "purl": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:068e286a-7f76-5efc-89f4-67acafd46300",
      "id": "CVE-2025-15599",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-15599 is fixed in version 3.1.6-tuxcare.7 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acba4f53-3a74-59a8-b38a-2f1680b16013",
      "id": "CVE-2025-26791",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-26791 is fixed in version 3.1.6-tuxcare.7 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ce44d86-1c1d-50e6-822e-88419f57deb0",
      "id": "CVE-2026-0540",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-0540 is fixed in version 3.1.6-tuxcare.7 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:453c4b3d-4226-5fb2-bbfd-b39bb5fbafd3",
      "id": "CVE-2026-41238",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41238 is fixed in version 3.1.6-tuxcare.7 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61e5d21b-9a91-50c4-b1c6-778d02b69962",
      "id": "CVE-2026-41239",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41239 is fixed in version 3.1.6-tuxcare.7 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:690a87e0-cac2-5cb2-a1c1-12801c287ccc",
      "id": "CVE-2026-41240",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41240 is fixed in version 3.1.6-tuxcare.7 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fafeb2a4-2e33-5dfe-b14c-af61f30004b5",
      "id": "CVE-2026-49458",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49458 is fixed in version 3.1.6-tuxcare.7 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c9d5455-0ecf-5b73-ab3d-f624ec55606d",
      "id": "CVE-2026-49459",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49459 is fixed in version 3.1.6-tuxcare.7 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f3e19ca-0ebf-5167-b66d-315345420eb2",
      "id": "CVE-2026-49978",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49978 is fixed in version 3.1.6-tuxcare.7 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ec30566-7f49-5e99-998c-1257a248d274",
      "id": "CVE-2026-65898",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65898 is fixed in version 3.1.6-tuxcare.7 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c5ed456-117b-5b81-bfe0-7aa37f044f36",
      "id": "CVE-2026-65899",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65899 is fixed in version 3.1.6-tuxcare.7 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15d5b987-403e-5712-afb0-58331b80e445",
      "id": "CVE-2026-65900",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65900 is fixed in version 3.1.6-tuxcare.7 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da54e389-83a9-538b-90a2-fe0724e229de",
      "id": "CVE-2026-65901",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65901 does not affect version 3.1.6-tuxcare.7 of DOMPurify. not_affected \u2014 Version 3.1.6 is not affected by CVE-2026-65901. The target contains a defensive mechanism that uses a realm-safe cached prototype getter (getNodeName) to validate element types, which bypasses attacker-controlled own properties set via Object.defineProperty. The CVE explicitly targets version 3.4.6, which is newer than the target version 3.1.6."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc35ba08-c63e-5d9e-8494-fa2d3fcb8773",
      "id": "CVE-2026-65902",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65902 is fixed in version 3.1.6-tuxcare.7 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb1df3ef-4d40-518c-accf-3e8819921eb4",
      "id": "CVE-2026-65903",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65903 does not affect version 3.1.6-tuxcare.7 of DOMPurify. not_affected \u2014 Target version 3.1.6-tuxcare.5 does not contain the vulnerable code pattern described in CVE-2026-65903. The CVE describes a short-circuit evaluation issue in v3.3.3 where ADD_TAGS as a function (via EXTRA_ELEMENT_HANDLING.tagCheck) can bypass FORBID_TAGS. In v3.1.6, the equivalent logic (CUSTOM_ELEMENT_HANDLING.tagNameCheck) includes an explicit guard at line 1538 that checks !FORBID_TAGS[tagN..."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea2d0604-c839-5994-9032-0edb5a30608e",
      "id": "CVE-2026-65912",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65912 does not affect version 3.1.6-tuxcare.7 of DOMPurify. not_affected \u2014 DOMPurify version 3.1.6 is not affected by CVE-2026-65912. The vulnerability requires predicate-based attribute allowlisting features (ADD_ATTR as a predicate function or EXTRA_ELEMENT_HANDLING.attributeCheck) that do not exist in this version. Version 3.1.6 predates these features entirely."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93214f9e-b24d-5abd-9bc8-f2951f75c78e",
      "id": "CVE-2026-65913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65913 is fixed in version 3.1.6-tuxcare.7 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6ac034c-3c74-51ab-bbd1-131a0cbf25a6",
      "id": "CVE-2026-65914",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65914 does not affect version 3.1.6-tuxcare.7 of DOMPurify. not_affected \u2014 DOMPurify 3.1.6-tuxcare.5 is not affected by CVE-2026-65914. The target version contains a runtime defense mechanism (SAFE_FOR_XML, enabled by default) that removes attributes containing closing tags for special parsing-context elements (xmp, script, iframe, noembed, noframes, noscript). This defense prevents the mutation-XSS attack described in the CVE when DOMPurify is used with default confi..."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdffb58f-06e0-57e8-9f54-9ce7682bdfbd",
      "id": "CVE-2026-66010",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-66010 is fixed in version 3.1.6-tuxcare.7 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4d47842-64f3-5dd1-9024-93b3e57f5960",
      "id": "CVE-2026-75838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-75838 affects version 3.1.6-tuxcare.7 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4ae81fd-555a-5d60-ac47-d47a5b42224d",
      "id": "GHSA-39q2-94rc-95cp",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-39q2-94rc-95cp is fixed in version 3.1.6-tuxcare.7 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0de1ac04-a68c-5b17-8d42-99ad60d1d11f",
      "id": "GHSA-55q2-fjhq-7xh7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-55q2-fjhq-7xh7 affects version 3.1.6-tuxcare.7 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7a0eff8-420b-56b5-af5f-2f6b3ec56c26",
      "id": "GHSA-76mc-f452-cxcm",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-76mc-f452-cxcm is fixed in version 3.1.6-tuxcare.7 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c83aeee-8fd3-58be-8d86-137d2e56c504",
      "id": "GHSA-c2j3-45gr-mqc4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-c2j3-45gr-mqc4 is fixed in version 3.1.6-tuxcare.7 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adad21ed-0fc3-5069-afaf-74266e61ea67",
      "id": "GHSA-cj63-jhhr-wcxv",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cj63-jhhr-wcxv is fixed in version 3.1.6-tuxcare.7 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a238b9c-4f23-50ae-aed9-f68312482ee5",
      "id": "GHSA-cjmm-f4jc-qw8r",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cjmm-f4jc-qw8r is fixed in version 3.1.6-tuxcare.7 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1844fb21-9772-5672-a8b9-c6608183e733",
      "id": "GHSA-cmwh-pvxp-8882",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cmwh-pvxp-8882 is fixed in version 3.1.6-tuxcare.7 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d05f54ae-e935-55df-b21a-e3f1343b9d10",
      "id": "GHSA-gvmj-g25r-r7wr",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-gvmj-g25r-r7wr is fixed in version 3.1.6-tuxcare.7 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4714be55-a6b9-5aaa-a051-262109e2c5d4",
      "id": "GHSA-h8r8-wccr-v5f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-h8r8-wccr-v5f2 is fixed in version 3.1.6-tuxcare.7 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9571d9ab-0240-5192-aeb7-5c2bee33365d",
      "id": "GHSA-vxr8-fq34-vvx9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-vxr8-fq34-vvx9 is fixed in version 3.1.6-tuxcare.7 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f3235d4-df8a-5217-b109-afe8be902f2d",
      "id": "GHSA-x4vx-rjvf-j5p4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x4vx-rjvf-j5p4 is fixed in version 3.1.6-tuxcare.7 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.7"
    }
  ]
}