{
  "@id": "urn:uuid:cc6ff084-6070-49f2-9a62-aaba8db0d719",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15599 is fixed in version 3.1.6-tuxcare.7 of dompurify.",
      "vulnerability": {
        "name": "CVE-2025-15599"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26791 is fixed in version 3.1.6-tuxcare.7 of dompurify.",
      "vulnerability": {
        "name": "CVE-2025-26791"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0540 is fixed in version 3.1.6-tuxcare.7 of dompurify.",
      "vulnerability": {
        "name": "CVE-2026-0540"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41238 is fixed in version 3.1.6-tuxcare.7 of dompurify.",
      "vulnerability": {
        "name": "CVE-2026-41238"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41239 is fixed in version 3.1.6-tuxcare.7 of dompurify.",
      "vulnerability": {
        "name": "CVE-2026-41239"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41240 is fixed in version 3.1.6-tuxcare.7 of dompurify.",
      "vulnerability": {
        "name": "CVE-2026-41240"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49458 is fixed in version 3.1.6-tuxcare.7 of dompurify.",
      "vulnerability": {
        "name": "CVE-2026-49458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49459 is fixed in version 3.1.6-tuxcare.7 of dompurify.",
      "vulnerability": {
        "name": "CVE-2026-49459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49978 is fixed in version 3.1.6-tuxcare.7 of dompurify.",
      "vulnerability": {
        "name": "CVE-2026-49978"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-65898 is fixed in version 3.1.6-tuxcare.7 of dompurify.",
      "vulnerability": {
        "name": "CVE-2026-65898"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-65899 is fixed in version 3.1.6-tuxcare.7 of dompurify.",
      "vulnerability": {
        "name": "CVE-2026-65899"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-65900 is fixed in version 3.1.6-tuxcare.7 of dompurify.",
      "vulnerability": {
        "name": "CVE-2026-65900"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-65901 does not affect version 3.1.6-tuxcare.7 of dompurify. not_affected \u2014 Version 3.1.6 is not affected by CVE-2026-65901. The target contains a defensive mechanism that uses a realm-safe cached prototype getter (getNodeName) to validate element types, which bypasses attacker-controlled own properties set via Object.defineProperty. The CVE explicitly targets version 3.4.6, which is newer than the target version 3.1.6.",
      "vulnerability": {
        "name": "CVE-2026-65901"
      },
      "impact_statement": "not_affected \u2014 Version 3.1.6 is not affected by CVE-2026-65901. The target contains a defensive mechanism that uses a realm-safe cached prototype getter (getNodeName) to validate element types, which bypasses attacker-controlled own properties set via Object.defineProperty. The CVE explicitly targets version 3.4.6, which is newer than the target version 3.1.6."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-65902 is fixed in version 3.1.6-tuxcare.7 of dompurify.",
      "vulnerability": {
        "name": "CVE-2026-65902"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-65903 does not affect version 3.1.6-tuxcare.7 of dompurify. not_affected \u2014 Target version 3.1.6-tuxcare.5 does not contain the vulnerable code pattern described in CVE-2026-65903. The CVE describes a short-circuit evaluation issue in v3.3.3 where ADD_TAGS as a function (via EXTRA_ELEMENT_HANDLING.tagCheck) can bypass FORBID_TAGS. In v3.1.6, the equivalent logic (CUSTOM_ELEMENT_HANDLING.tagNameCheck) includes an explicit guard at line 1538 that checks !FORBID_TAGS[tagN...",
      "vulnerability": {
        "name": "CVE-2026-65903"
      },
      "impact_statement": "not_affected \u2014 Target version 3.1.6-tuxcare.5 does not contain the vulnerable code pattern described in CVE-2026-65903. The CVE describes a short-circuit evaluation issue in v3.3.3 where ADD_TAGS as a function (via EXTRA_ELEMENT_HANDLING.tagCheck) can bypass FORBID_TAGS. In v3.1.6, the equivalent logic (CUSTOM_ELEMENT_HANDLING.tagNameCheck) includes an explicit guard at line 1538 that checks !FORBID_TAGS[tagN..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-65912 does not affect version 3.1.6-tuxcare.7 of dompurify. not_affected \u2014 DOMPurify version 3.1.6 is not affected by CVE-2026-65912. The vulnerability requires predicate-based attribute allowlisting features (ADD_ATTR as a predicate function or EXTRA_ELEMENT_HANDLING.attributeCheck) that do not exist in this version. Version 3.1.6 predates these features entirely.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-65912"
      },
      "impact_statement": "not_affected \u2014 DOMPurify version 3.1.6 is not affected by CVE-2026-65912. The vulnerability requires predicate-based attribute allowlisting features (ADD_ATTR as a predicate function or EXTRA_ELEMENT_HANDLING.attributeCheck) that do not exist in this version. Version 3.1.6 predates these features entirely."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-65913 is fixed in version 3.1.6-tuxcare.7 of dompurify.",
      "vulnerability": {
        "name": "CVE-2026-65913"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-65914 does not affect version 3.1.6-tuxcare.7 of dompurify. not_affected \u2014 DOMPurify 3.1.6-tuxcare.5 is not affected by CVE-2026-65914. The target version contains a runtime defense mechanism (SAFE_FOR_XML, enabled by default) that removes attributes containing closing tags for special parsing-context elements (xmp, script, iframe, noembed, noframes, noscript). This defense prevents the mutation-XSS attack described in the CVE when DOMPurify is used with default confi...",
      "vulnerability": {
        "name": "CVE-2026-65914"
      },
      "impact_statement": "not_affected \u2014 DOMPurify 3.1.6-tuxcare.5 is not affected by CVE-2026-65914. The target version contains a runtime defense mechanism (SAFE_FOR_XML, enabled by default) that removes attributes containing closing tags for special parsing-context elements (xmp, script, iframe, noembed, noframes, noscript). This defense prevents the mutation-XSS attack described in the CVE when DOMPurify is used with default confi..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-66010 is fixed in version 3.1.6-tuxcare.7 of dompurify.",
      "vulnerability": {
        "name": "CVE-2026-66010"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-75838 affects version 3.1.6-tuxcare.7 of dompurify, and is fixed in 3.1.6-tuxcare.8.",
      "vulnerability": {
        "name": "CVE-2026-75838"
      },
      "action_statement": "Vulnerability CVE-2026-75838 affects version 3.1.6-tuxcare.7 of dompurify, and is fixed in 3.1.6-tuxcare.8."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-39q2-94rc-95cp is fixed in version 3.1.6-tuxcare.7 of dompurify.",
      "vulnerability": {
        "name": "GHSA-39q2-94rc-95cp"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-55q2-fjhq-7xh7 affects version 3.1.6-tuxcare.7 of dompurify.",
      "vulnerability": {
        "name": "GHSA-55q2-fjhq-7xh7"
      },
      "action_statement": "Vulnerability GHSA-55q2-fjhq-7xh7 affects version 3.1.6-tuxcare.7 of dompurify."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-76mc-f452-cxcm is fixed in version 3.1.6-tuxcare.7 of dompurify.",
      "vulnerability": {
        "name": "GHSA-76mc-f452-cxcm"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-c2j3-45gr-mqc4 is fixed in version 3.1.6-tuxcare.7 of dompurify.",
      "vulnerability": {
        "name": "GHSA-c2j3-45gr-mqc4"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-cj63-jhhr-wcxv is fixed in version 3.1.6-tuxcare.7 of dompurify.",
      "vulnerability": {
        "name": "GHSA-cj63-jhhr-wcxv"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-cjmm-f4jc-qw8r is fixed in version 3.1.6-tuxcare.7 of dompurify.",
      "vulnerability": {
        "name": "GHSA-cjmm-f4jc-qw8r"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-cmwh-pvxp-8882 is fixed in version 3.1.6-tuxcare.7 of dompurify.",
      "vulnerability": {
        "name": "GHSA-cmwh-pvxp-8882"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gvmj-g25r-r7wr is fixed in version 3.1.6-tuxcare.7 of dompurify.",
      "vulnerability": {
        "name": "GHSA-gvmj-g25r-r7wr"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-h8r8-wccr-v5f2 is fixed in version 3.1.6-tuxcare.7 of dompurify.",
      "vulnerability": {
        "name": "GHSA-h8r8-wccr-v5f2"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-vxr8-fq34-vvx9 is fixed in version 3.1.6-tuxcare.7 of dompurify.",
      "vulnerability": {
        "name": "GHSA-vxr8-fq34-vvx9"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.1.6-tuxcare.7",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.1.6-tuxcare.7"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x4vx-rjvf-j5p4 is fixed in version 3.1.6-tuxcare.7 of dompurify.",
      "vulnerability": {
        "name": "GHSA-x4vx-rjvf-j5p4"
      }
    }
  ]
}
