{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3d31c7fc-b211-52f8-947c-4795783cd363",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "dompurify",
      "purl": "pkg:npm/dompurify@3.1.6-tuxcare.8",
      "type": "library",
      "bom-ref": "pkg:npm/dompurify@3.1.6-tuxcare.8",
      "version": "3.1.6-tuxcare.8",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-15599",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:932e0993-938e-5101-885a-1a9062621ea8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-15599 is fixed in version 3.1.6-tuxcare.8 of dompurify."
      }
    },
    {
      "id": "CVE-2025-26791",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:4a491c89-8e02-5a55-9aa5-c4f4d1b4e389",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-26791 is fixed in version 3.1.6-tuxcare.8 of dompurify."
      }
    },
    {
      "id": "CVE-2026-0540",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:18b13c5e-50b1-5771-972b-8f4e9bc98ff3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-0540 is fixed in version 3.1.6-tuxcare.8 of dompurify."
      }
    },
    {
      "id": "CVE-2026-41238",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:8e23471b-b421-5323-b3fa-4ccd9dca9ad2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41238 is fixed in version 3.1.6-tuxcare.8 of dompurify."
      }
    },
    {
      "id": "CVE-2026-41239",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:88352e0b-7eef-5ccc-b7c5-356fdacd0efc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41239 is fixed in version 3.1.6-tuxcare.8 of dompurify."
      }
    },
    {
      "id": "CVE-2026-41240",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:aceeae19-825b-58b4-82b1-2297fcebd2cd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41240 is fixed in version 3.1.6-tuxcare.8 of dompurify."
      }
    },
    {
      "id": "CVE-2026-49458",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:9c36efb3-b516-53fd-a8b5-ffd0166a3d98",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49458 is fixed in version 3.1.6-tuxcare.8 of dompurify."
      }
    },
    {
      "id": "CVE-2026-49459",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:57ca1a0a-f53f-5684-8686-461fe045da6b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49459 is fixed in version 3.1.6-tuxcare.8 of dompurify."
      }
    },
    {
      "id": "CVE-2026-49978",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:1bc224dd-5ab3-5c50-8839-3690f0f6a306",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49978 is fixed in version 3.1.6-tuxcare.8 of dompurify."
      }
    },
    {
      "id": "CVE-2026-65898",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:c0cf2c61-499a-59a3-972d-1dc77f6c36df",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65898 is fixed in version 3.1.6-tuxcare.8 of dompurify."
      }
    },
    {
      "id": "CVE-2026-65899",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:377ac009-133e-5837-843d-2e93ff8a80ad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65899 is fixed in version 3.1.6-tuxcare.8 of dompurify."
      }
    },
    {
      "id": "CVE-2026-65900",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:120f799c-9676-54da-9de2-dfa8605a9485",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65900 is fixed in version 3.1.6-tuxcare.8 of dompurify."
      }
    },
    {
      "id": "CVE-2026-65901",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:31c496dc-7824-5eb5-a62c-684836a6312e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65901 does not affect version 3.1.6-tuxcare.8 of dompurify. not_affected \u2014 Version 3.1.6 is not affected by CVE-2026-65901. The target contains a defensive mechanism that uses a realm-safe cached prototype getter (getNodeName) to validate element types, which bypasses attacker-controlled own properties set via Object.defineProperty. The CVE explicitly targets version 3.4.6, which is newer than the target version 3.1.6.",
        "justification": "protected_at_runtime"
      }
    },
    {
      "id": "CVE-2026-65902",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:d978d14e-e9ac-55fe-9fec-3671108709f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65902 is fixed in version 3.1.6-tuxcare.8 of dompurify."
      }
    },
    {
      "id": "CVE-2026-65903",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:2574007d-b24c-5697-80ed-ef01fa3d131a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65903 does not affect version 3.1.6-tuxcare.8 of dompurify. not_affected \u2014 Target version 3.1.6-tuxcare.5 does not contain the vulnerable code pattern described in CVE-2026-65903. The CVE describes a short-circuit evaluation issue in v3.3.3 where ADD_TAGS as a function (via EXTRA_ELEMENT_HANDLING.tagCheck) can bypass FORBID_TAGS. In v3.1.6, the equivalent logic (CUSTOM_ELEMENT_HANDLING.tagNameCheck) includes an explicit guard at line 1538 that checks !FORBID_TAGS[tagN...",
        "justification": "protected_at_runtime"
      }
    },
    {
      "id": "CVE-2026-65912",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:b15b7004-36d4-5488-bb63-e4b1f435ca15",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65912 does not affect version 3.1.6-tuxcare.8 of dompurify. not_affected \u2014 DOMPurify version 3.1.6 is not affected by CVE-2026-65912. The vulnerability requires predicate-based attribute allowlisting features (ADD_ATTR as a predicate function or EXTRA_ELEMENT_HANDLING.attributeCheck) that do not exist in this version. Version 3.1.6 predates these features entirely.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-65913",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:ef792080-e106-5187-95d0-39d26b1d153c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65913 is fixed in version 3.1.6-tuxcare.8 of dompurify."
      }
    },
    {
      "id": "CVE-2026-65914",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:8489e86d-0307-5546-bbe4-93cf8eeac7f9",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65914 does not affect version 3.1.6-tuxcare.8 of dompurify. not_affected \u2014 DOMPurify 3.1.6-tuxcare.5 is not affected by CVE-2026-65914. The target version contains a runtime defense mechanism (SAFE_FOR_XML, enabled by default) that removes attributes containing closing tags for special parsing-context elements (xmp, script, iframe, noembed, noframes, noscript). This defense prevents the mutation-XSS attack described in the CVE when DOMPurify is used with default confi...",
        "justification": "protected_at_runtime"
      }
    },
    {
      "id": "CVE-2026-66010",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:8f0208de-51d5-5f17-857e-ce4bd149186a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-66010 is fixed in version 3.1.6-tuxcare.8 of dompurify."
      }
    },
    {
      "id": "CVE-2026-75838",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:5e063541-a99a-5406-b7f0-9d73c5090172",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-75838 is fixed in version 3.1.6-tuxcare.8 of dompurify."
      }
    },
    {
      "id": "GHSA-39q2-94rc-95cp",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:34962ed6-4c23-5f35-9009-03366087f189",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-39q2-94rc-95cp is fixed in version 3.1.6-tuxcare.8 of dompurify."
      }
    },
    {
      "id": "GHSA-55q2-fjhq-7xh7",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:1ac2da1a-ecf7-57cc-9c43-15003e899e78",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-55q2-fjhq-7xh7 affects version 3.1.6-tuxcare.8 of dompurify."
      }
    },
    {
      "id": "GHSA-76mc-f452-cxcm",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:7b03460e-e4a0-5f10-bf59-cac87c7b32a5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-76mc-f452-cxcm is fixed in version 3.1.6-tuxcare.8 of dompurify."
      }
    },
    {
      "id": "GHSA-c2j3-45gr-mqc4",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:dfca7f6b-988e-51f2-bf20-6823dc654037",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-c2j3-45gr-mqc4 is fixed in version 3.1.6-tuxcare.8 of dompurify."
      }
    },
    {
      "id": "GHSA-cj63-jhhr-wcxv",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:c5cf14a4-c13f-549e-9318-ed76e1d0c5e1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cj63-jhhr-wcxv is fixed in version 3.1.6-tuxcare.8 of dompurify."
      }
    },
    {
      "id": "GHSA-cjmm-f4jc-qw8r",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:d44a1e46-3192-5848-8c89-35f2cf635dbe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cjmm-f4jc-qw8r is fixed in version 3.1.6-tuxcare.8 of dompurify."
      }
    },
    {
      "id": "GHSA-cmwh-pvxp-8882",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6b477b0d-3175-586d-aa32-5bb10fbde022",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cmwh-pvxp-8882 is fixed in version 3.1.6-tuxcare.8 of dompurify."
      }
    },
    {
      "id": "GHSA-gvmj-g25r-r7wr",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:35c4fe36-96b3-5d1d-9591-c963cfb8a2d6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-gvmj-g25r-r7wr is fixed in version 3.1.6-tuxcare.8 of dompurify."
      }
    },
    {
      "id": "GHSA-h8r8-wccr-v5f2",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:0d363f53-fd1f-5f89-9434-13bee58ec41c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-h8r8-wccr-v5f2 is fixed in version 3.1.6-tuxcare.8 of dompurify."
      }
    },
    {
      "id": "GHSA-vxr8-fq34-vvx9",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:bac47cca-5a9b-5f73-80ed-2617abff931c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-vxr8-fq34-vvx9 is fixed in version 3.1.6-tuxcare.8 of dompurify."
      }
    },
    {
      "id": "GHSA-x4vx-rjvf-j5p4",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:9048970c-2ed3-5500-9cee-7283f42d8edb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x4vx-rjvf-j5p4 is fixed in version 3.1.6-tuxcare.8 of dompurify."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/dompurify@3.1.6-tuxcare.8"
    }
  ]
}