{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:56e76590-c6ca-5fac-83f5-161285a6ee9c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/dompurify@3.2.7-tuxcare.1",
      "type": "library",
      "name": "dompurify",
      "version": "3.2.7-tuxcare.1",
      "purl": "pkg:npm/dompurify@3.2.7-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2fe4174f-09ba-57f1-bb8e-662f4f498ecf",
      "id": "CVE-2017-16137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-16137 is fixed in version 3.2.7-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73c61f4c-c909-51fe-8b04-b5680e8090fb",
      "id": "CVE-2026-0540",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-0540 affects version 3.2.7-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:607df431-8dcd-5e62-a625-4fc6db60d9e3",
      "id": "CVE-2026-41238",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41238 is fixed in version 3.2.7-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c631d986-4bb1-55c7-a560-fd759e49cc67",
      "id": "CVE-2026-41239",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41239 is fixed in version 3.2.7-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56ed3905-a142-5814-8f90-2ed01ce67665",
      "id": "CVE-2026-41240",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41240 does not affect version 3.2.7-tuxcare.1 of dompurify. not_affected \u2014 DOMPurify version 3.2.7 is NOT AFFECTED by CVE-2026-41240. The vulnerability requires the EXTRA_ELEMENT_HANDLING.tagCheck feature and function-based ADD_TAGS configuration, which were introduced in version 3.3.0. Version 3.2.7 only supports array-based ADD_TAGS and lacks the EXTRA_ELEMENT_HANDLING mechanism entirely, making the attack vector described in the CVE impossible to trigger."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:923410ce-c700-55fa-beba-bf50e3b7d4cf",
      "id": "CVE-2026-49458",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49458 is fixed in version 3.2.7-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1df959cb-36e6-529d-bba3-cbe1f7786347",
      "id": "CVE-2026-49459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49459 affects version 3.2.7-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b97e3a14-4a1f-5428-b083-e86e42c5a668",
      "id": "CVE-2026-49978",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49978 affects version 3.2.7-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a8cccd5-ea8d-55d5-995a-4e222cab81f1",
      "id": "CVE-2026-65898",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65898 is fixed in version 3.2.7-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f122425a-38fa-5ff6-a1f9-a52d9d8d0b86",
      "id": "CVE-2026-65899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65899 affects version 3.2.7-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:880dd8c0-de51-5338-be5a-32f6ed0b2b67",
      "id": "CVE-2026-65900",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65900 is fixed in version 3.2.7-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7f16acf-2269-5a08-b1fd-05541971b336",
      "id": "CVE-2026-65901",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65901 is fixed in version 3.2.7-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a418ed6e-5c75-5bc6-b800-8a8dedf035b3",
      "id": "CVE-2026-65902",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65902 affects version 3.2.7-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17240a47-797f-5bb4-a3e5-b368b4ca352b",
      "id": "CVE-2026-65903",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65903 does not affect version 3.2.7-tuxcare.1 of dompurify. not_affected \u2014 DOMPurify 3.2.7 is NOT affected by CVE-2026-65903. The vulnerability requires EXTRA_ELEMENT_HANDLING.tagCheck, a feature that allows ADD_TAGS to be used as a function, which was introduced in later versions (v3.3.3+). Version 3.2.7 only supports ADD_TAGS as a string array and does not have the EXTRA_ELEMENT_HANDLING mechanism. The existing CUSTOM_ELEMENT_HANDLING in 3.2.7 correctly prioritizes ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ce066dc-44e3-5825-8892-e73ba8e61f6a",
      "id": "CVE-2026-65912",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65912 does not affect version 3.2.7-tuxcare.1 of dompurify. not_affected \u2014 DOMPurify version 3.2.7 is not affected by CVE-2026-65912. The vulnerability requires ADD_ATTR to be provided as a predicate function via EXTRA_ELEMENT_HANDLING.attributeCheck, which bypasses URI validation when returning true. This function-based ADD_ATTR feature was introduced in version 3.3.0 (PR #1150) AFTER the 3.2.7 release. The target version only supports ADD_ATTR as a string array (typ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d451a6d8-d543-5617-b77b-3ecf7ac91cb4",
      "id": "CVE-2026-65913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65913 is fixed in version 3.2.7-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b700a9a8-22f5-5310-ac1a-20d910651d16",
      "id": "CVE-2026-65914",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65914 is fixed in version 3.2.7-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b58b5874-e06c-5774-af93-6ec79fc9c381",
      "id": "GHSA-55q2-fjhq-7xh7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-55q2-fjhq-7xh7 is fixed in version 3.2.7-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9165a14f-fd6a-5428-8675-f0d0057a2895",
      "id": "GHSA-c2j3-45gr-mqc4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-c2j3-45gr-mqc4 is fixed in version 3.2.7-tuxcare.1 of dompurify."
      },
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/dompurify@3.2.7-tuxcare.1"
    }
  ]
}