{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a076969c-a374-5152-a610-ff1549233bd2",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "dompurify",
      "purl": "pkg:npm/dompurify@3.2.7-tuxcare.2",
      "type": "library",
      "bom-ref": "pkg:npm/dompurify@3.2.7-tuxcare.2",
      "version": "3.2.7-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2026-0540",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:44877f8e-0be7-50b5-83c8-00d3538f5ece",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-0540 is fixed in version 3.2.7-tuxcare.2 of dompurify."
      }
    },
    {
      "id": "CVE-2026-41238",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f5507b77-39ba-5783-8d31-d28980262272",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41238 is fixed in version 3.2.7-tuxcare.2 of dompurify."
      }
    },
    {
      "id": "CVE-2026-41239",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a195ecce-1a9b-5cec-a340-92599a66b6b4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41239 is fixed in version 3.2.7-tuxcare.2 of dompurify."
      }
    },
    {
      "id": "CVE-2026-41240",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fdcc1723-f3f5-5f71-a077-333101d67ce2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41240 does not affect version 3.2.7-tuxcare.2 of dompurify. not_affected \u2014 DOMPurify version 3.2.7 is NOT AFFECTED by CVE-2026-41240. The vulnerability requires the EXTRA_ELEMENT_HANDLING.tagCheck feature and function-based ADD_TAGS configuration, which were introduced in version 3.3.0. Version 3.2.7 only supports array-based ADD_TAGS and lacks the EXTRA_ELEMENT_HANDLING mechanism entirely, making the attack vector described in the CVE impossible to trigger.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-49458",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b5417627-357d-5238-95ad-1c1b764b60f0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49458 is fixed in version 3.2.7-tuxcare.2 of dompurify."
      }
    },
    {
      "id": "CVE-2026-49459",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c0a5c3dc-fba2-531f-bca3-a948bbd0982e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49459 is fixed in version 3.2.7-tuxcare.2 of dompurify."
      }
    },
    {
      "id": "CVE-2026-49978",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:67fbf7cb-f897-5ea5-a35b-3c4f897e4ba8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49978 affects version 3.2.7-tuxcare.2 of dompurify, and is fixed in 3.2.7-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-65898",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1b00c280-b447-5717-aaaf-2225019579d5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65898 is fixed in version 3.2.7-tuxcare.2 of dompurify."
      }
    },
    {
      "id": "CVE-2026-65899",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3ae83dd1-9004-5f7b-a908-d6cf7051aa90",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65899 affects version 3.2.7-tuxcare.2 of dompurify, and is fixed in 3.2.7-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-65900",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5ec7ecb8-b86f-500d-8110-a87f2cd10c70",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65900 is fixed in version 3.2.7-tuxcare.2 of dompurify."
      }
    },
    {
      "id": "CVE-2026-65901",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b4c1b70d-7c3d-5a02-9869-7bb0263befed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65901 is fixed in version 3.2.7-tuxcare.2 of dompurify."
      }
    },
    {
      "id": "CVE-2026-65902",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5f9eadb9-d3c8-5a7e-ac8c-d53ada4dd685",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65902 affects version 3.2.7-tuxcare.2 of dompurify, and is fixed in 3.2.7-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-65903",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f067f036-b449-59d3-a975-e44243bf1f1d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65903 does not affect version 3.2.7-tuxcare.2 of dompurify. not_affected \u2014 DOMPurify 3.2.7 is NOT affected by CVE-2026-65903. The vulnerability requires EXTRA_ELEMENT_HANDLING.tagCheck, a feature that allows ADD_TAGS to be used as a function, which was introduced in later versions (v3.3.3+). Version 3.2.7 only supports ADD_TAGS as a string array and does not have the EXTRA_ELEMENT_HANDLING mechanism. The existing CUSTOM_ELEMENT_HANDLING in 3.2.7 correctly prioritizes ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-65912",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9f0826e5-1caf-55ed-a25e-5592c78d0d77",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65912 does not affect version 3.2.7-tuxcare.2 of dompurify. not_affected \u2014 DOMPurify version 3.2.7 is not affected by CVE-2026-65912. The vulnerability requires ADD_ATTR to be provided as a predicate function via EXTRA_ELEMENT_HANDLING.attributeCheck, which bypasses URI validation when returning true. This function-based ADD_ATTR feature was introduced in version 3.3.0 (PR #1150) AFTER the 3.2.7 release. The target version only supports ADD_ATTR as a string array (typ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-65913",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:650e6b22-9750-5839-929c-4602a36dd1b9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65913 is fixed in version 3.2.7-tuxcare.2 of dompurify."
      }
    },
    {
      "id": "CVE-2026-65914",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3ee61cf5-bd19-52ab-9725-cae88f51665d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65914 is fixed in version 3.2.7-tuxcare.2 of dompurify."
      }
    },
    {
      "id": "CVE-2026-66010",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:192e65ed-69fa-5039-bb1f-cd5532ee00de",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-66010 affects version 3.2.7-tuxcare.2 of dompurify, and is fixed in 3.2.7-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-75838",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:574aefb6-e061-5f6c-ab4c-c0abcf8c7c5d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-75838 is fixed in version 3.2.7-tuxcare.2 of dompurify."
      }
    },
    {
      "id": "GHSA-55q2-fjhq-7xh7",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e98dc994-7481-5072-9702-bd87cbe5dd99",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-55q2-fjhq-7xh7 is fixed in version 3.2.7-tuxcare.2 of dompurify."
      }
    },
    {
      "id": "GHSA-c2j3-45gr-mqc4",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3a16c263-09f0-5fb9-b987-aedf529658d2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-c2j3-45gr-mqc4 is fixed in version 3.2.7-tuxcare.2 of dompurify."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/dompurify@3.2.7-tuxcare.2"
    }
  ]
}