{
  "@id": "urn:uuid:77b2addf-24b4-4a6f-8572-d6573dc63bb8",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.2.7-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.2.7-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0540 is fixed in version 3.2.7-tuxcare.3 of dompurify.",
      "vulnerability": {
        "name": "CVE-2026-0540"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.2.7-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.2.7-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41238 is fixed in version 3.2.7-tuxcare.3 of dompurify.",
      "vulnerability": {
        "name": "CVE-2026-41238"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.2.7-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.2.7-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41239 is fixed in version 3.2.7-tuxcare.3 of dompurify.",
      "vulnerability": {
        "name": "CVE-2026-41239"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.2.7-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.2.7-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41240 does not affect version 3.2.7-tuxcare.3 of dompurify. not_affected \u2014 DOMPurify version 3.2.7 is NOT AFFECTED by CVE-2026-41240. The vulnerability requires the EXTRA_ELEMENT_HANDLING.tagCheck feature and function-based ADD_TAGS configuration, which were introduced in version 3.3.0. Version 3.2.7 only supports array-based ADD_TAGS and lacks the EXTRA_ELEMENT_HANDLING mechanism entirely, making the attack vector described in the CVE impossible to trigger.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41240"
      },
      "impact_statement": "not_affected \u2014 DOMPurify version 3.2.7 is NOT AFFECTED by CVE-2026-41240. The vulnerability requires the EXTRA_ELEMENT_HANDLING.tagCheck feature and function-based ADD_TAGS configuration, which were introduced in version 3.3.0. Version 3.2.7 only supports array-based ADD_TAGS and lacks the EXTRA_ELEMENT_HANDLING mechanism entirely, making the attack vector described in the CVE impossible to trigger."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.2.7-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.2.7-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49458 is fixed in version 3.2.7-tuxcare.3 of dompurify.",
      "vulnerability": {
        "name": "CVE-2026-49458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.2.7-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.2.7-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49459 is fixed in version 3.2.7-tuxcare.3 of dompurify.",
      "vulnerability": {
        "name": "CVE-2026-49459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.2.7-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.2.7-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49978 is fixed in version 3.2.7-tuxcare.3 of dompurify.",
      "vulnerability": {
        "name": "CVE-2026-49978"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.2.7-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.2.7-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-65898 is fixed in version 3.2.7-tuxcare.3 of dompurify.",
      "vulnerability": {
        "name": "CVE-2026-65898"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.2.7-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.2.7-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-65899 is fixed in version 3.2.7-tuxcare.3 of dompurify.",
      "vulnerability": {
        "name": "CVE-2026-65899"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.2.7-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.2.7-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-65900 is fixed in version 3.2.7-tuxcare.3 of dompurify.",
      "vulnerability": {
        "name": "CVE-2026-65900"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.2.7-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.2.7-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-65901 is fixed in version 3.2.7-tuxcare.3 of dompurify.",
      "vulnerability": {
        "name": "CVE-2026-65901"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.2.7-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.2.7-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-65902 is fixed in version 3.2.7-tuxcare.3 of dompurify.",
      "vulnerability": {
        "name": "CVE-2026-65902"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.2.7-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.2.7-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-65903 does not affect version 3.2.7-tuxcare.3 of dompurify. not_affected \u2014 DOMPurify 3.2.7 is NOT affected by CVE-2026-65903. The vulnerability requires EXTRA_ELEMENT_HANDLING.tagCheck, a feature that allows ADD_TAGS to be used as a function, which was introduced in later versions (v3.3.3+). Version 3.2.7 only supports ADD_TAGS as a string array and does not have the EXTRA_ELEMENT_HANDLING mechanism. The existing CUSTOM_ELEMENT_HANDLING in 3.2.7 correctly prioritizes ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-65903"
      },
      "impact_statement": "not_affected \u2014 DOMPurify 3.2.7 is NOT affected by CVE-2026-65903. The vulnerability requires EXTRA_ELEMENT_HANDLING.tagCheck, a feature that allows ADD_TAGS to be used as a function, which was introduced in later versions (v3.3.3+). Version 3.2.7 only supports ADD_TAGS as a string array and does not have the EXTRA_ELEMENT_HANDLING mechanism. The existing CUSTOM_ELEMENT_HANDLING in 3.2.7 correctly prioritizes ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.2.7-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.2.7-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-65912 does not affect version 3.2.7-tuxcare.3 of dompurify. not_affected \u2014 DOMPurify version 3.2.7 is not affected by CVE-2026-65912. The vulnerability requires ADD_ATTR to be provided as a predicate function via EXTRA_ELEMENT_HANDLING.attributeCheck, which bypasses URI validation when returning true. This function-based ADD_ATTR feature was introduced in version 3.3.0 (PR #1150) AFTER the 3.2.7 release. The target version only supports ADD_ATTR as a string array (typ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-65912"
      },
      "impact_statement": "not_affected \u2014 DOMPurify version 3.2.7 is not affected by CVE-2026-65912. The vulnerability requires ADD_ATTR to be provided as a predicate function via EXTRA_ELEMENT_HANDLING.attributeCheck, which bypasses URI validation when returning true. This function-based ADD_ATTR feature was introduced in version 3.3.0 (PR #1150) AFTER the 3.2.7 release. The target version only supports ADD_ATTR as a string array (typ..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.2.7-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.2.7-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-65913 is fixed in version 3.2.7-tuxcare.3 of dompurify.",
      "vulnerability": {
        "name": "CVE-2026-65913"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.2.7-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.2.7-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-65914 is fixed in version 3.2.7-tuxcare.3 of dompurify.",
      "vulnerability": {
        "name": "CVE-2026-65914"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.2.7-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.2.7-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-66010 is fixed in version 3.2.7-tuxcare.3 of dompurify.",
      "vulnerability": {
        "name": "CVE-2026-66010"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.2.7-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.2.7-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-75838 is fixed in version 3.2.7-tuxcare.3 of dompurify.",
      "vulnerability": {
        "name": "CVE-2026-75838"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.2.7-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.2.7-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-55q2-fjhq-7xh7 is fixed in version 3.2.7-tuxcare.3 of dompurify.",
      "vulnerability": {
        "name": "GHSA-55q2-fjhq-7xh7"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/dompurify@3.2.7-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/dompurify@3.2.7-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-c2j3-45gr-mqc4 is fixed in version 3.2.7-tuxcare.3 of dompurify.",
      "vulnerability": {
        "name": "GHSA-c2j3-45gr-mqc4"
      }
    }
  ]
}
