{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ec049203-6e4d-5b7e-83a4-4e125a6b5d8d",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "dompurify",
      "purl": "pkg:npm/dompurify@3.2.7-tuxcare.3",
      "type": "library",
      "bom-ref": "pkg:npm/dompurify@3.2.7-tuxcare.3",
      "version": "3.2.7-tuxcare.3",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2026-0540",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:1c0f57e6-54fe-5694-94ed-f1b2e367e629",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-0540 is fixed in version 3.2.7-tuxcare.3 of dompurify."
      }
    },
    {
      "id": "CVE-2026-41238",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:9332a9b2-e4c0-5371-9e9f-ba706dc4f0c1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41238 is fixed in version 3.2.7-tuxcare.3 of dompurify."
      }
    },
    {
      "id": "CVE-2026-41239",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:adc66cf4-c9a8-5420-9872-9eaed766ec72",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41239 is fixed in version 3.2.7-tuxcare.3 of dompurify."
      }
    },
    {
      "id": "CVE-2026-41240",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:70dcdb99-ebea-5caf-af5e-259608945b8e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41240 does not affect version 3.2.7-tuxcare.3 of dompurify. not_affected \u2014 DOMPurify version 3.2.7 is NOT AFFECTED by CVE-2026-41240. The vulnerability requires the EXTRA_ELEMENT_HANDLING.tagCheck feature and function-based ADD_TAGS configuration, which were introduced in version 3.3.0. Version 3.2.7 only supports array-based ADD_TAGS and lacks the EXTRA_ELEMENT_HANDLING mechanism entirely, making the attack vector described in the CVE impossible to trigger.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-49458",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:14f763ff-bb1e-5e7a-a7c4-5720b115ec46",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49458 is fixed in version 3.2.7-tuxcare.3 of dompurify."
      }
    },
    {
      "id": "CVE-2026-49459",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:f115ba7a-9d07-53a1-b2a8-ddb551c466bc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49459 is fixed in version 3.2.7-tuxcare.3 of dompurify."
      }
    },
    {
      "id": "CVE-2026-49978",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:6c21eee4-a473-533d-9234-b2569d041f00",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49978 is fixed in version 3.2.7-tuxcare.3 of dompurify."
      }
    },
    {
      "id": "CVE-2026-65898",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:1baed130-3692-5711-a416-eab487e1ad4b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65898 is fixed in version 3.2.7-tuxcare.3 of dompurify."
      }
    },
    {
      "id": "CVE-2026-65899",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:c965e158-a91b-59aa-9377-0611d0b6073b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65899 is fixed in version 3.2.7-tuxcare.3 of dompurify."
      }
    },
    {
      "id": "CVE-2026-65900",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:76d36eae-88af-5139-9c58-c0778b9d94f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65900 is fixed in version 3.2.7-tuxcare.3 of dompurify."
      }
    },
    {
      "id": "CVE-2026-65901",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:4a063d5b-9ea1-5e06-a957-efad029319a5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65901 is fixed in version 3.2.7-tuxcare.3 of dompurify."
      }
    },
    {
      "id": "CVE-2026-65902",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:60ed1f1a-57d7-57bb-a28c-57712782f653",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65902 is fixed in version 3.2.7-tuxcare.3 of dompurify."
      }
    },
    {
      "id": "CVE-2026-65903",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:2d38eb08-0150-5ce3-b47d-e4ff5d9406cc",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65903 does not affect version 3.2.7-tuxcare.3 of dompurify. not_affected \u2014 DOMPurify 3.2.7 is NOT affected by CVE-2026-65903. The vulnerability requires EXTRA_ELEMENT_HANDLING.tagCheck, a feature that allows ADD_TAGS to be used as a function, which was introduced in later versions (v3.3.3+). Version 3.2.7 only supports ADD_TAGS as a string array and does not have the EXTRA_ELEMENT_HANDLING mechanism. The existing CUSTOM_ELEMENT_HANDLING in 3.2.7 correctly prioritizes ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-65912",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:56fd726a-6b7b-5c93-aa3e-1f5be8c9efea",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65912 does not affect version 3.2.7-tuxcare.3 of dompurify. not_affected \u2014 DOMPurify version 3.2.7 is not affected by CVE-2026-65912. The vulnerability requires ADD_ATTR to be provided as a predicate function via EXTRA_ELEMENT_HANDLING.attributeCheck, which bypasses URI validation when returning true. This function-based ADD_ATTR feature was introduced in version 3.3.0 (PR #1150) AFTER the 3.2.7 release. The target version only supports ADD_ATTR as a string array (typ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-65913",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:125e1c1e-922a-5cbc-bd64-6ccf61e2ea24",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65913 is fixed in version 3.2.7-tuxcare.3 of dompurify."
      }
    },
    {
      "id": "CVE-2026-65914",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:8f68893d-f8d4-5e98-8b00-64a247f91de5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-65914 is fixed in version 3.2.7-tuxcare.3 of dompurify."
      }
    },
    {
      "id": "CVE-2026-66010",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:4014cef4-7e2d-5a10-8d03-6900c0257a20",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-66010 is fixed in version 3.2.7-tuxcare.3 of dompurify."
      }
    },
    {
      "id": "CVE-2026-75838",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:259d8fe1-ecbd-5f5e-9391-446715a2ec2a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-75838 is fixed in version 3.2.7-tuxcare.3 of dompurify."
      }
    },
    {
      "id": "GHSA-55q2-fjhq-7xh7",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:0d817d59-062c-5ec6-b18d-c0658358ca92",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-55q2-fjhq-7xh7 is fixed in version 3.2.7-tuxcare.3 of dompurify."
      }
    },
    {
      "id": "GHSA-c2j3-45gr-mqc4",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.2.7-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:c91783ba-7a4d-5c8e-a168-773770dfb70c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-c2j3-45gr-mqc4 is fixed in version 3.2.7-tuxcare.3 of dompurify."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/dompurify@3.2.7-tuxcare.3"
    }
  ]
}