{
  "@id": "urn:uuid:b6440b5f-3af4-4922-ba7c-7901298a8e45",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/sanitize-html@1.27.5-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/sanitize-html@1.27.5-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2019-25225 is fixed in version 1.27.5-tuxcare.3 of sanitize-html.",
      "vulnerability": {
        "name": "CVE-2019-25225"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/sanitize-html@1.27.5-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/sanitize-html@1.27.5-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-26539 is fixed in version 1.27.5-tuxcare.3 of sanitize-html.",
      "vulnerability": {
        "name": "CVE-2021-26539"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/sanitize-html@1.27.5-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/sanitize-html@1.27.5-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-26540 is fixed in version 1.27.5-tuxcare.3 of sanitize-html.",
      "vulnerability": {
        "name": "CVE-2021-26540"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/sanitize-html@1.27.5-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/sanitize-html@1.27.5-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25887 is fixed in version 1.27.5-tuxcare.3 of sanitize-html.",
      "vulnerability": {
        "name": "CVE-2022-25887"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/sanitize-html@1.27.5-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/sanitize-html@1.27.5-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-21501 is fixed in version 1.27.5-tuxcare.3 of sanitize-html.",
      "vulnerability": {
        "name": "CVE-2024-21501"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/sanitize-html@1.27.5-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/sanitize-html@1.27.5-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44990 does not affect version 1.27.5-tuxcare.3 of sanitize-html. not_affected \u2014 Version 1.27.5 does not contain the vulnerability pattern described in CVE-2026-44990. The vulnerable code (special-casing xmp tags for unescaped text output) does not exist in this version. Instead, xmp content is properly escaped via HTML entity encoding, preventing XSS attacks.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-44990"
      },
      "impact_statement": "not_affected \u2014 Version 1.27.5 does not contain the vulnerability pattern described in CVE-2026-44990. The vulnerable code (special-casing xmp tags for unescaped text output) does not exist in this version. Instead, xmp content is properly escaped via HTML entity encoding, preventing XSS attacks."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/sanitize-html@1.27.5-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/sanitize-html@1.27.5-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53606 affects version 1.27.5-tuxcare.3 of sanitize-html, and is fixed in 1.27.5-tuxcare.4.",
      "vulnerability": {
        "name": "CVE-2026-53606"
      },
      "action_statement": "Vulnerability CVE-2026-53606 affects version 1.27.5-tuxcare.3 of sanitize-html, and is fixed in 1.27.5-tuxcare.4."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/sanitize-html@1.27.5-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/sanitize-html@1.27.5-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-63670 does not affect version 1.27.5-tuxcare.3 of sanitize-html. not_affected \u2014 sanitize-html version 1.27.5 is NOT affected by CVE-2026-63670. The vulnerable code path (raw-text pass-through for textarea/xmp elements) that existed in the 2.x branch (\u22642.17.5) was never present in the 1.27.x codebase. This version always escapes text content via escapeHtml() except for script/style tags, preventing the mutation-XSS. The htmlparser2 4.1.0 parser used in 1.27.5 also does not ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-63670"
      },
      "impact_statement": "not_affected \u2014 sanitize-html version 1.27.5 is NOT affected by CVE-2026-63670. The vulnerable code path (raw-text pass-through for textarea/xmp elements) that existed in the 2.x branch (\u22642.17.5) was never present in the 1.27.x codebase. This version always escapes text content via escapeHtml() except for script/style tags, preventing the mutation-XSS. The htmlparser2 4.1.0 parser used in 1.27.5 also does not ..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/sanitize-html@1.27.5-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/sanitize-html@1.27.5-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84371 affects version 1.27.5-tuxcare.3 of sanitize-html, and is fixed in 1.27.5-tuxcare.5.",
      "vulnerability": {
        "name": "CVE-2026-84371"
      },
      "action_statement": "Vulnerability CVE-2026-84371 affects version 1.27.5-tuxcare.3 of sanitize-html, and is fixed in 1.27.5-tuxcare.5."
    }
  ]
}
