{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:eb55ca1c-1415-50de-9b06-4a866481dea8",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.2",
      "type": "library",
      "name": "DOMPurify",
      "version": "3.2.7-tuxcare.2",
      "purl": "pkg:npm/DOMPurify@3.2.7-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:fac8d4b6-9d7e-5c4a-8ea0-d59a7aa17a1d",
      "id": "CVE-2017-16137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-16137 is fixed in version 3.2.7-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:455305c6-623b-56ae-9b56-86ed023650a6",
      "id": "CVE-2026-0540",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-0540 is fixed in version 3.2.7-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:749cd2bb-4454-586f-a9c8-2cecf06ec3fe",
      "id": "CVE-2026-41238",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41238 is fixed in version 3.2.7-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c05a960-d8b3-5bba-b009-67b7f97968d5",
      "id": "CVE-2026-41239",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41239 is fixed in version 3.2.7-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b711751b-eb82-5c7d-8fc7-363f9e8ebb2e",
      "id": "CVE-2026-41240",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41240 does not affect version 3.2.7-tuxcare.2 of DOMPurify. not_affected \u2014 DOMPurify version 3.2.7 is NOT AFFECTED by CVE-2026-41240. The vulnerability requires the EXTRA_ELEMENT_HANDLING.tagCheck feature and function-based ADD_TAGS configuration, which were introduced in version 3.3.0. Version 3.2.7 only supports array-based ADD_TAGS and lacks the EXTRA_ELEMENT_HANDLING mechanism entirely, making the attack vector described in the CVE impossible to trigger."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d9cda05-39db-575e-a664-bfb4023cf346",
      "id": "CVE-2026-49458",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49458 is fixed in version 3.2.7-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b24b378-21fe-53d6-ba33-87472377eb01",
      "id": "CVE-2026-49459",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49459 is fixed in version 3.2.7-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a419461-7b9d-5abc-a4c7-32f6429b710c",
      "id": "CVE-2026-49978",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49978 affects version 3.2.7-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6194ce04-cbf5-5d52-83b1-244fb9962e84",
      "id": "CVE-2026-65898",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65898 is fixed in version 3.2.7-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5af08577-8393-58a8-a468-0c3bb6f011b3",
      "id": "CVE-2026-65899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65899 affects version 3.2.7-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f8f9e94-0207-57b0-901b-6b5e7eb3527e",
      "id": "CVE-2026-65900",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65900 is fixed in version 3.2.7-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdb75118-2cdc-5ac1-8508-0e9b26aab796",
      "id": "CVE-2026-65901",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65901 is fixed in version 3.2.7-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f260e0b-923d-5f20-9259-2ef2f58f33fd",
      "id": "CVE-2026-65902",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65902 affects version 3.2.7-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73747916-48e4-59c0-a21b-5cfc4bd5a9ed",
      "id": "CVE-2026-65903",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65903 does not affect version 3.2.7-tuxcare.2 of DOMPurify. not_affected \u2014 DOMPurify 3.2.7 is NOT affected by CVE-2026-65903. The vulnerability requires EXTRA_ELEMENT_HANDLING.tagCheck, a feature that allows ADD_TAGS to be used as a function, which was introduced in later versions (v3.3.3+). Version 3.2.7 only supports ADD_TAGS as a string array and does not have the EXTRA_ELEMENT_HANDLING mechanism. The existing CUSTOM_ELEMENT_HANDLING in 3.2.7 correctly prioritizes ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da1acd5d-9687-527d-929e-4d37ac57b10b",
      "id": "CVE-2026-65912",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65912 does not affect version 3.2.7-tuxcare.2 of DOMPurify. not_affected \u2014 DOMPurify version 3.2.7 is not affected by CVE-2026-65912. The vulnerability requires ADD_ATTR to be provided as a predicate function via EXTRA_ELEMENT_HANDLING.attributeCheck, which bypasses URI validation when returning true. This function-based ADD_ATTR feature was introduced in version 3.3.0 (PR #1150) AFTER the 3.2.7 release. The target version only supports ADD_ATTR as a string array (typ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06d8bd42-0462-5638-9aa0-8dd57fcb54ed",
      "id": "CVE-2026-65913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65913 is fixed in version 3.2.7-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfee6c73-ff70-58b3-b772-4a7939886657",
      "id": "CVE-2026-65914",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65914 is fixed in version 3.2.7-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:020b53f0-991d-5a28-aa6a-58b4c6fb806a",
      "id": "CVE-2026-75838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-75838 is fixed in version 3.2.7-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19cd1873-caa5-5191-a536-6b6d848dab31",
      "id": "GHSA-55q2-fjhq-7xh7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-55q2-fjhq-7xh7 is fixed in version 3.2.7-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c49e9c9-7187-5f4b-9b00-cc1aca8e7c88",
      "id": "GHSA-c2j3-45gr-mqc4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-c2j3-45gr-mqc4 is fixed in version 3.2.7-tuxcare.2 of DOMPurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/DOMPurify@3.2.7-tuxcare.2"
    }
  ]
}