{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f76d0e2b-8f79-5ac0-ae48-9efda7cc0717",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "dompurify",
      "purl": "pkg:npm/dompurify@3.0.3",
      "type": "library",
      "bom-ref": "pkg:npm/dompurify@3.0.3",
      "version": "3.0.3",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2024-45801",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:3b3e5d8b-cec3-5a87-8b0d-b5c012238d3f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45801 affects version 3.0.3 of dompurify, and is fixed in 3.0.3-tuxcare.1."
      }
    },
    {
      "id": "CVE-2024-47875",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:bf063d79-e3bb-5bc8-8e6c-9de9efa74513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-47875 affects version 3.0.3 of dompurify, and is fixed in 3.0.3-tuxcare.1."
      }
    },
    {
      "id": "CVE-2025-26791",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:dfc694a7-4c70-5bc4-b9af-6133d0ca3d0b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-26791 affects version 3.0.3 of dompurify, and is fixed in 3.0.3-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-0540",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:081ac18e-28be-593c-8399-b1e9b02bbac1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-0540 affects version 3.0.3 of dompurify, and is fixed in 3.0.3-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-41238",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:464727a0-c17c-5b38-a82a-f2dae4765999",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41238 affects version 3.0.3 of dompurify, and is fixed in 3.0.3-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-41239",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:cb92d342-4400-5b14-b3a7-5d3fb8755092",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41239 affects version 3.0.3 of dompurify, and is fixed in 3.0.3-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-41240",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:d37da033-fc56-559b-8f64-4efb63404746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41240 affects version 3.0.3 of dompurify, and is fixed in 3.0.3-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-49458",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:f58fbef6-dcca-5a3d-b36a-fa6e506321bc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49458 affects version 3.0.3 of dompurify, and is fixed in 3.0.3-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-49459",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:d8c7ff69-3442-5d21-a3d4-a39346441664",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49459 affects version 3.0.3 of dompurify, and is fixed in 3.0.3-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-49978",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:121d2e3f-6bb8-5fce-8f7f-875f7128e610",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49978 affects version 3.0.3 of dompurify, and is fixed in 3.0.3-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-65898",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:a51d1206-a22b-5eb6-9481-37be7b5fd98c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65898 affects version 3.0.3 of dompurify, and is fixed in 3.0.3-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-65899",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:2cb175db-7f5f-54e7-924b-b09185c696c1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65899 affects version 3.0.3 of dompurify, and is fixed in 3.0.3-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-65900",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:b39bb626-e756-536b-83c7-3984d3876c17",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65900 affects version 3.0.3 of dompurify, and is fixed in 3.0.3-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-65901",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:139a4c01-4d7a-5519-b0ad-7624090edf63",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65901 affects version 3.0.3 of dompurify."
      }
    },
    {
      "id": "CVE-2026-65902",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:f6ed96eb-a86e-59e0-964e-a544ad4c6a79",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65902 affects version 3.0.3 of dompurify, and is fixed in 3.0.3-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-65903",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:2e5d65a5-0a30-52f8-b44d-94c4bf7c678b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65903 does not affect version 3.0.3 of dompurify. not_affected \u2014 Target version 3.0.3-tuxcare.3 is not affected by CVE-2026-65903. The vulnerable code pattern described in the CVE (single-line condition with short-circuit evaluation bypassing FORBID_TAGS) does not exist in this version. The target uses a nested conditional structure that explicitly checks !FORBID_TAGS[tagName] before allowing custom element tagNameCheck evaluation, which is the exact mitigat..."
      }
    },
    {
      "id": "CVE-2026-65912",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:bffb80e6-33db-51bd-8dd5-c8683e7d599d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65912 affects version 3.0.3 of dompurify, and is fixed in 3.0.3-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-65913",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:7189b7e8-61b4-53a2-969f-0dff9f8f1bb1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65913 affects version 3.0.3 of dompurify, and is fixed in 3.0.3-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-65914",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:4c24e2ea-7d5b-55fe-bed2-439eeff80656",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65914 affects version 3.0.3 of dompurify, and is fixed in 3.0.3-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-66010",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:be629ce0-33f4-522e-9ea3-1500539e5f55",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-66010 affects version 3.0.3 of dompurify, and is fixed in 3.0.3-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-75838",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:d2f96969-124f-51c2-ad05-c7a642fb7f98",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-75838 affects version 3.0.3 of dompurify, and is fixed in 3.0.3-tuxcare.5."
      }
    },
    {
      "id": "GHSA-39q2-94rc-95cp",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:656211db-de83-55c4-93e0-a04eda721d01",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-39q2-94rc-95cp affects version 3.0.3 of dompurify, and is fixed in 3.0.3-tuxcare.1."
      }
    },
    {
      "id": "GHSA-55q2-fjhq-7xh7",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:905e6301-bda3-50c3-b47c-5f2d520e6062",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-55q2-fjhq-7xh7 affects version 3.0.3 of dompurify."
      }
    },
    {
      "id": "GHSA-76mc-f452-cxcm",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:f8c64ce6-e2eb-5695-8c5c-f0d09676ba0f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-76mc-f452-cxcm affects version 3.0.3 of dompurify, and is fixed in 3.0.3-tuxcare.2."
      }
    },
    {
      "id": "GHSA-c2j3-45gr-mqc4",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:adc76961-af39-5ac9-92b5-dd48aa35ffea",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-c2j3-45gr-mqc4 affects version 3.0.3 of dompurify, and is fixed in 3.0.3-tuxcare.3."
      }
    },
    {
      "id": "GHSA-cj63-jhhr-wcxv",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:c26716e7-4311-5030-80dc-a13f87d10d72",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-cj63-jhhr-wcxv affects version 3.0.3 of dompurify, and is fixed in 3.0.3-tuxcare.1."
      }
    },
    {
      "id": "GHSA-cjmm-f4jc-qw8r",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:24ed9409-9e28-5b41-9612-62db42831a58",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-cjmm-f4jc-qw8r affects version 3.0.3 of dompurify, and is fixed in 3.0.3-tuxcare.1."
      }
    },
    {
      "id": "GHSA-cmwh-pvxp-8882",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:fccdd44e-d250-544c-83f9-b8f255e49d7d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-cmwh-pvxp-8882 affects version 3.0.3 of dompurify, and is fixed in 3.0.3-tuxcare.2."
      }
    },
    {
      "id": "GHSA-gvmj-g25r-r7wr",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:52d0db4c-b3a0-5277-9e8f-8fb65317faa1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-gvmj-g25r-r7wr affects version 3.0.3 of dompurify, and is fixed in 3.0.3-tuxcare.2."
      }
    },
    {
      "id": "GHSA-h8r8-wccr-v5f2",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:4cb1ed49-be11-5958-9b75-3c9dad4decfa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-h8r8-wccr-v5f2 affects version 3.0.3 of dompurify, and is fixed in 3.0.3-tuxcare.1."
      }
    },
    {
      "id": "GHSA-vxr8-fq34-vvx9",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:60713cf0-1cab-5388-b8c5-77822187e407",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-vxr8-fq34-vvx9 affects version 3.0.3 of dompurify, and is fixed in 3.0.3-tuxcare.2."
      }
    },
    {
      "id": "GHSA-x4vx-rjvf-j5p4",
      "affects": [
        {
          "ref": "pkg:npm/dompurify@3.0.3"
        }
      ],
      "bom-ref": "urn:uuid:bc441943-c4ff-58e3-ae4a-9834a81f8354",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x4vx-rjvf-j5p4 affects version 3.0.3 of dompurify, and is fixed in 3.0.3-tuxcare.2."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/dompurify@3.0.3"
    }
  ]
}