{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2224c927-530b-54ff-be07-5992f2631e5c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.1",
      "type": "library",
      "name": "DOMPurify",
      "version": "3.2.7-tuxcare.1",
      "purl": "pkg:npm/DOMPurify@3.2.7-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9738499c-50ce-5fa3-a5c8-2ce293b93a9c",
      "id": "CVE-2017-16137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-16137 is fixed in version 3.2.7-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db523e07-ac2d-5a19-9f83-d015b50f203c",
      "id": "CVE-2026-0540",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-0540 affects version 3.2.7-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3fe07fe-397d-5a02-93ab-9827c82e00d5",
      "id": "CVE-2026-41238",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41238 is fixed in version 3.2.7-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08c662bb-c998-51c6-9c9a-6ce6f4fedcfb",
      "id": "CVE-2026-41239",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41239 is fixed in version 3.2.7-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23d8b046-3f3b-50cc-be32-6c24c4fa954a",
      "id": "CVE-2026-41240",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41240 does not affect version 3.2.7-tuxcare.1 of DOMPurify. not_affected \u2014 DOMPurify version 3.2.7 is NOT AFFECTED by CVE-2026-41240. The vulnerability requires the EXTRA_ELEMENT_HANDLING.tagCheck feature and function-based ADD_TAGS configuration, which were introduced in version 3.3.0. Version 3.2.7 only supports array-based ADD_TAGS and lacks the EXTRA_ELEMENT_HANDLING mechanism entirely, making the attack vector described in the CVE impossible to trigger."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15f85c03-764d-554b-9ac8-e737b0b1cfbb",
      "id": "CVE-2026-49458",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49458 is fixed in version 3.2.7-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8783fb8-cb76-5232-badb-f214995fa204",
      "id": "CVE-2026-49459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49459 affects version 3.2.7-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67932730-7939-5078-a3d8-0524f6bd6f69",
      "id": "CVE-2026-49978",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49978 affects version 3.2.7-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2466467e-8264-57cf-a039-c16b89c261ea",
      "id": "CVE-2026-65898",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65898 is fixed in version 3.2.7-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:173a3e50-3dca-57df-95d7-e0e01a6a2da1",
      "id": "CVE-2026-65899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65899 affects version 3.2.7-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8d3109f-d0d6-50fb-9268-4fbae9a52254",
      "id": "CVE-2026-65900",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65900 is fixed in version 3.2.7-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:317779ff-9a87-50a8-96e1-efd2bdd6ed31",
      "id": "CVE-2026-65901",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65901 is fixed in version 3.2.7-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ac3ab7d-3884-514f-8236-c890d6d26deb",
      "id": "CVE-2026-65902",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65902 affects version 3.2.7-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92c01acb-c1be-5183-b16a-b50b998330f9",
      "id": "CVE-2026-65903",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65903 does not affect version 3.2.7-tuxcare.1 of DOMPurify. not_affected \u2014 DOMPurify 3.2.7 is NOT affected by CVE-2026-65903. The vulnerability requires EXTRA_ELEMENT_HANDLING.tagCheck, a feature that allows ADD_TAGS to be used as a function, which was introduced in later versions (v3.3.3+). Version 3.2.7 only supports ADD_TAGS as a string array and does not have the EXTRA_ELEMENT_HANDLING mechanism. The existing CUSTOM_ELEMENT_HANDLING in 3.2.7 correctly prioritizes ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:233c416b-58cc-5feb-ae33-1413c18a76db",
      "id": "CVE-2026-65912",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65912 does not affect version 3.2.7-tuxcare.1 of DOMPurify. not_affected \u2014 DOMPurify version 3.2.7 is not affected by CVE-2026-65912. The vulnerability requires ADD_ATTR to be provided as a predicate function via EXTRA_ELEMENT_HANDLING.attributeCheck, which bypasses URI validation when returning true. This function-based ADD_ATTR feature was introduced in version 3.3.0 (PR #1150) AFTER the 3.2.7 release. The target version only supports ADD_ATTR as a string array (typ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6050e047-b40e-5dec-b0c5-29ffe6f9d07c",
      "id": "CVE-2026-65913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65913 is fixed in version 3.2.7-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0444c78c-e7c5-58cc-ae21-ce112da6a88b",
      "id": "CVE-2026-65914",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65914 is fixed in version 3.2.7-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:401a9259-6c2f-514d-9d40-7168a2cba91d",
      "id": "CVE-2026-75838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-75838 affects version 3.2.7-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db68266a-61bb-53eb-9d07-5ca0467ac23a",
      "id": "GHSA-55q2-fjhq-7xh7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-55q2-fjhq-7xh7 is fixed in version 3.2.7-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd44169c-d99c-518c-850c-3c523cf81148",
      "id": "GHSA-c2j3-45gr-mqc4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-c2j3-45gr-mqc4 is fixed in version 3.2.7-tuxcare.1 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.1"
    }
  ]
}