{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:77339615-3003-55f0-9787-267adff4ab35",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/dompurify@3.1.6-tuxcare.7",
      "type": "library",
      "name": "dompurify",
      "version": "3.1.6-tuxcare.7",
      "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:fd583a87-f16e-5940-9740-a46b0254536a",
      "id": "CVE-2025-15599",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-15599 is fixed in version 3.1.6-tuxcare.7 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a48c1275-95a3-5487-8323-4015bf52b426",
      "id": "CVE-2025-26791",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-26791 is fixed in version 3.1.6-tuxcare.7 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52a04d23-99a2-5f2b-a393-1cd7cd94453b",
      "id": "CVE-2026-0540",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-0540 is fixed in version 3.1.6-tuxcare.7 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c670c71a-c30f-537c-b1b2-c1c9b4f57e5a",
      "id": "CVE-2026-41238",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41238 is fixed in version 3.1.6-tuxcare.7 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:853ae513-3a8e-5e27-b4a0-bbd60c5709d9",
      "id": "CVE-2026-41239",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41239 is fixed in version 3.1.6-tuxcare.7 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b39b1055-b1cf-5c7d-9853-38033c6c0c39",
      "id": "CVE-2026-41240",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41240 is fixed in version 3.1.6-tuxcare.7 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75519a8b-4c1b-5a27-a5c1-93ab6f170f7e",
      "id": "CVE-2026-49458",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49458 is fixed in version 3.1.6-tuxcare.7 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea1ef32d-c860-5d8f-b7c7-7bfcaeb33465",
      "id": "CVE-2026-49459",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49459 is fixed in version 3.1.6-tuxcare.7 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7e1af28-9ae1-5afe-bdd1-f634501bee09",
      "id": "CVE-2026-49978",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49978 is fixed in version 3.1.6-tuxcare.7 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37cf3896-4125-5bee-a36f-3c6c17a87b07",
      "id": "CVE-2026-65898",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65898 is fixed in version 3.1.6-tuxcare.7 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78ce29ca-1dfc-59c3-85a0-8019aa561c0a",
      "id": "CVE-2026-65899",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65899 is fixed in version 3.1.6-tuxcare.7 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66f57b09-63d3-50de-be2a-f6258563f904",
      "id": "CVE-2026-65900",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65900 is fixed in version 3.1.6-tuxcare.7 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7dc8cb55-d5a6-55d0-8406-d0551a467829",
      "id": "CVE-2026-65901",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65901 does not affect version 3.1.6-tuxcare.7 of dompurify. not_affected \u2014 Version 3.1.6 is not affected by CVE-2026-65901. The target contains a defensive mechanism that uses a realm-safe cached prototype getter (getNodeName) to validate element types, which bypasses attacker-controlled own properties set via Object.defineProperty. The CVE explicitly targets version 3.4.6, which is newer than the target version 3.1.6."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f05cae55-e40f-51cd-9966-724aaae64233",
      "id": "CVE-2026-65902",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65902 is fixed in version 3.1.6-tuxcare.7 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5afeafe-53c5-5d75-98c6-35ae94a012b7",
      "id": "CVE-2026-65903",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65903 does not affect version 3.1.6-tuxcare.7 of dompurify. not_affected \u2014 Target version 3.1.6-tuxcare.5 does not contain the vulnerable code pattern described in CVE-2026-65903. The CVE describes a short-circuit evaluation issue in v3.3.3 where ADD_TAGS as a function (via EXTRA_ELEMENT_HANDLING.tagCheck) can bypass FORBID_TAGS. In v3.1.6, the equivalent logic (CUSTOM_ELEMENT_HANDLING.tagNameCheck) includes an explicit guard at line 1538 that checks !FORBID_TAGS[tagN..."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68e7504b-e3aa-5a61-8ca5-6475ff6e6bb3",
      "id": "CVE-2026-65912",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65912 does not affect version 3.1.6-tuxcare.7 of dompurify. not_affected \u2014 DOMPurify version 3.1.6 is not affected by CVE-2026-65912. The vulnerability requires predicate-based attribute allowlisting features (ADD_ATTR as a predicate function or EXTRA_ELEMENT_HANDLING.attributeCheck) that do not exist in this version. Version 3.1.6 predates these features entirely."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72c5db4f-4602-5d7b-8bfe-caf1601e5b03",
      "id": "CVE-2026-65913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65913 is fixed in version 3.1.6-tuxcare.7 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:845edce8-61b7-55bd-9916-72510d4d927a",
      "id": "CVE-2026-65914",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65914 does not affect version 3.1.6-tuxcare.7 of dompurify. not_affected \u2014 DOMPurify 3.1.6-tuxcare.5 is not affected by CVE-2026-65914. The target version contains a runtime defense mechanism (SAFE_FOR_XML, enabled by default) that removes attributes containing closing tags for special parsing-context elements (xmp, script, iframe, noembed, noframes, noscript). This defense prevents the mutation-XSS attack described in the CVE when DOMPurify is used with default confi..."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5b6b756-6057-503c-87f1-85074a8f6352",
      "id": "CVE-2026-66010",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-66010 is fixed in version 3.1.6-tuxcare.7 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac7f20c6-d31a-57bc-9fce-4ccbb6ac83ae",
      "id": "GHSA-39q2-94rc-95cp",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-39q2-94rc-95cp is fixed in version 3.1.6-tuxcare.7 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e0c82e5-10a3-52c4-9362-7fe4a3834a6c",
      "id": "GHSA-55q2-fjhq-7xh7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-55q2-fjhq-7xh7 affects version 3.1.6-tuxcare.7 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f01a724-f5b9-5d12-935a-4512251e130d",
      "id": "GHSA-76mc-f452-cxcm",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-76mc-f452-cxcm is fixed in version 3.1.6-tuxcare.7 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02528fb4-6cbe-50bf-b4b8-734bdebd654c",
      "id": "GHSA-c2j3-45gr-mqc4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-c2j3-45gr-mqc4 is fixed in version 3.1.6-tuxcare.7 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6ba3211-c62c-5123-89a6-3237d68f0be3",
      "id": "GHSA-cj63-jhhr-wcxv",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cj63-jhhr-wcxv is fixed in version 3.1.6-tuxcare.7 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:098d0b3a-801d-5ed3-8922-624b84de004a",
      "id": "GHSA-cjmm-f4jc-qw8r",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cjmm-f4jc-qw8r is fixed in version 3.1.6-tuxcare.7 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:693d64e2-34be-51cc-b5a5-b255f11fe154",
      "id": "GHSA-cmwh-pvxp-8882",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cmwh-pvxp-8882 is fixed in version 3.1.6-tuxcare.7 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc616cb3-5833-504a-bb24-77c056129159",
      "id": "GHSA-gvmj-g25r-r7wr",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-gvmj-g25r-r7wr is fixed in version 3.1.6-tuxcare.7 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3867d4c9-d945-5dd7-ace2-950770560690",
      "id": "GHSA-h8r8-wccr-v5f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-h8r8-wccr-v5f2 is fixed in version 3.1.6-tuxcare.7 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27dc35e6-4599-5245-8da1-35015dcbf945",
      "id": "GHSA-vxr8-fq34-vvx9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-vxr8-fq34-vvx9 is fixed in version 3.1.6-tuxcare.7 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58ad5b83-48c9-5bd0-8bf0-6925ae09d16b",
      "id": "GHSA-x4vx-rjvf-j5p4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x4vx-rjvf-j5p4 is fixed in version 3.1.6-tuxcare.7 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/dompurify@3.1.6-tuxcare.7"
    }
  ]
}