{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1c19dab7-d526-5761-b14c-c60803f2b0cb",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8",
      "type": "library",
      "name": "DOMPurify",
      "version": "3.1.6-tuxcare.8",
      "purl": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:589a8d52-e9e8-54fe-9138-e4e613e2c316",
      "id": "CVE-2025-15599",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-15599 is fixed in version 3.1.6-tuxcare.8 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eaad3b90-c447-50b3-8a49-971b16c02613",
      "id": "CVE-2025-26791",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-26791 is fixed in version 3.1.6-tuxcare.8 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df5caa66-4219-5eec-8ccd-c93417290687",
      "id": "CVE-2026-0540",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-0540 is fixed in version 3.1.6-tuxcare.8 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14b1b9bc-0be1-5e1f-beee-84ca28318391",
      "id": "CVE-2026-41238",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41238 is fixed in version 3.1.6-tuxcare.8 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:577802fe-0e66-550a-ab40-0186e3303481",
      "id": "CVE-2026-41239",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41239 is fixed in version 3.1.6-tuxcare.8 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70db1539-8950-54db-8b49-64da6b481358",
      "id": "CVE-2026-41240",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41240 is fixed in version 3.1.6-tuxcare.8 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e621f66-6a0d-5415-a1e0-ec1312be2ff2",
      "id": "CVE-2026-49458",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49458 is fixed in version 3.1.6-tuxcare.8 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abac02d4-fcac-5d4e-8ce5-14b081b56253",
      "id": "CVE-2026-49459",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49459 is fixed in version 3.1.6-tuxcare.8 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a018a5b1-bd8d-59ca-a128-c2d307d6e639",
      "id": "CVE-2026-49978",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49978 is fixed in version 3.1.6-tuxcare.8 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55189e77-d421-519d-a182-0d323300a9da",
      "id": "CVE-2026-65898",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65898 is fixed in version 3.1.6-tuxcare.8 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29d94df6-95d3-54dd-bbe4-c3fcea6805ad",
      "id": "CVE-2026-65899",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65899 is fixed in version 3.1.6-tuxcare.8 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c109291-45ec-5eaf-9a83-d01008ec2576",
      "id": "CVE-2026-65900",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65900 is fixed in version 3.1.6-tuxcare.8 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd057c0e-8898-5134-aacf-7fd5e8a20da9",
      "id": "CVE-2026-65901",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65901 does not affect version 3.1.6-tuxcare.8 of DOMPurify. not_affected \u2014 Version 3.1.6 is not affected by CVE-2026-65901. The target contains a defensive mechanism that uses a realm-safe cached prototype getter (getNodeName) to validate element types, which bypasses attacker-controlled own properties set via Object.defineProperty. The CVE explicitly targets version 3.4.6, which is newer than the target version 3.1.6."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a8bd153-3c9c-5b19-8ec8-a2c50a4b1360",
      "id": "CVE-2026-65902",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65902 is fixed in version 3.1.6-tuxcare.8 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8b28de7-dd88-5253-9e8a-5fabc7c2d719",
      "id": "CVE-2026-65903",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65903 does not affect version 3.1.6-tuxcare.8 of DOMPurify. not_affected \u2014 Target version 3.1.6-tuxcare.5 does not contain the vulnerable code pattern described in CVE-2026-65903. The CVE describes a short-circuit evaluation issue in v3.3.3 where ADD_TAGS as a function (via EXTRA_ELEMENT_HANDLING.tagCheck) can bypass FORBID_TAGS. In v3.1.6, the equivalent logic (CUSTOM_ELEMENT_HANDLING.tagNameCheck) includes an explicit guard at line 1538 that checks !FORBID_TAGS[tagN..."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:301c9b53-cce7-5633-b658-1a36ae0bf1ba",
      "id": "CVE-2026-65912",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65912 does not affect version 3.1.6-tuxcare.8 of DOMPurify. not_affected \u2014 DOMPurify version 3.1.6 is not affected by CVE-2026-65912. The vulnerability requires predicate-based attribute allowlisting features (ADD_ATTR as a predicate function or EXTRA_ELEMENT_HANDLING.attributeCheck) that do not exist in this version. Version 3.1.6 predates these features entirely."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8b00058-2a2a-588b-8206-f42039e3ba3b",
      "id": "CVE-2026-65913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65913 is fixed in version 3.1.6-tuxcare.8 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8aaae07f-387f-5637-a687-dddaec1c62af",
      "id": "CVE-2026-65914",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65914 does not affect version 3.1.6-tuxcare.8 of DOMPurify. not_affected \u2014 DOMPurify 3.1.6-tuxcare.5 is not affected by CVE-2026-65914. The target version contains a runtime defense mechanism (SAFE_FOR_XML, enabled by default) that removes attributes containing closing tags for special parsing-context elements (xmp, script, iframe, noembed, noframes, noscript). This defense prevents the mutation-XSS attack described in the CVE when DOMPurify is used with default confi..."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c51a0e4f-3231-528f-bcf6-b737a3882f1e",
      "id": "CVE-2026-66010",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-66010 is fixed in version 3.1.6-tuxcare.8 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ae15d6f-0c69-5384-8e54-a910da24dc14",
      "id": "CVE-2026-75838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-75838 is fixed in version 3.1.6-tuxcare.8 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36ae9f7b-bfcb-542b-94c2-cbd497a1c539",
      "id": "GHSA-39q2-94rc-95cp",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-39q2-94rc-95cp is fixed in version 3.1.6-tuxcare.8 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39b09326-015b-5a42-a95f-dfdfef133597",
      "id": "GHSA-55q2-fjhq-7xh7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-55q2-fjhq-7xh7 affects version 3.1.6-tuxcare.8 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:faa163b9-c3c1-5b82-a9b6-d5e7824aa713",
      "id": "GHSA-76mc-f452-cxcm",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-76mc-f452-cxcm is fixed in version 3.1.6-tuxcare.8 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd69a8b4-0bbd-523a-8943-86480636b858",
      "id": "GHSA-c2j3-45gr-mqc4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-c2j3-45gr-mqc4 is fixed in version 3.1.6-tuxcare.8 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da824029-a9a0-5e47-9a1f-40d0fc86348f",
      "id": "GHSA-cj63-jhhr-wcxv",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cj63-jhhr-wcxv is fixed in version 3.1.6-tuxcare.8 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8eee47ff-32b9-5d94-928a-75fe70582824",
      "id": "GHSA-cjmm-f4jc-qw8r",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cjmm-f4jc-qw8r is fixed in version 3.1.6-tuxcare.8 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fbc1713-1a2f-56ba-94b6-768a4e793967",
      "id": "GHSA-cmwh-pvxp-8882",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cmwh-pvxp-8882 is fixed in version 3.1.6-tuxcare.8 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:013ee87f-c67c-54ea-a24d-e0b9ca017d68",
      "id": "GHSA-gvmj-g25r-r7wr",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-gvmj-g25r-r7wr is fixed in version 3.1.6-tuxcare.8 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74d074a5-6030-590f-a61e-27bcc54b2ae3",
      "id": "GHSA-h8r8-wccr-v5f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-h8r8-wccr-v5f2 is fixed in version 3.1.6-tuxcare.8 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:183d6be1-a555-5c4b-94d2-648deb7afd81",
      "id": "GHSA-vxr8-fq34-vvx9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-vxr8-fq34-vvx9 is fixed in version 3.1.6-tuxcare.8 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e0fb83d-d52f-5f8e-ab7b-68db3e5911f0",
      "id": "GHSA-x4vx-rjvf-j5p4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x4vx-rjvf-j5p4 is fixed in version 3.1.6-tuxcare.8 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/DOMPurify@3.1.6-tuxcare.8"
    }
  ]
}