{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-0540",
        "tracking": {
            "current_release_date": "2026-04-02T21:23:50.389395Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-0540",
            "initial_release_date": "2026-03-03T17:38:50.400209Z",
            "revision_history": [
                {
                    "date": "2026-03-03T17:38:50.400209Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| Products connected (1).| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-03T17:38:53.132101Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-03-03T18:27:28.176025Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-03T18:27:30.680229Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-03T18:38:56.767953Z",
                    "number": "5",
                    "summary": "References created (1).| References removed (1)."
                },
                {
                    "date": "2026-03-03T19:39:01.356227Z",
                    "number": "6",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-03-03T20:27:19.230211Z",
                    "number": "7",
                    "summary": "References created (1).| References removed (1)."
                },
                {
                    "date": "2026-03-04T00:43:54.208687Z",
                    "number": "8",
                    "summary": "Source created.| CVE status created. (valid)| Products connected (1)."
                },
                {
                    "date": "2026-03-04T00:44:00.922771Z",
                    "number": "9",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-04T06:43:30.842254Z",
                    "number": "10",
                    "summary": "Description created for source."
                },
                {
                    "date": "2026-03-04T12:46:01.883532Z",
                    "number": "11",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (72).| Product Identifiers created (24).| Product Remediations created (72).| References created (5).| CWES updated (1).| Vendor_assessment created."
                },
                {
                    "date": "2026-03-04T12:46:14.302284Z",
                    "number": "12",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-04T15:34:22.225955Z",
                    "number": "13",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-04T21:51:17.527612Z",
                    "number": "14",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (6).| CWES updated (1)."
                },
                {
                    "date": "2026-03-04T21:51:19.772063Z",
                    "number": "15",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-05T00:20:50.903141Z",
                    "number": "16",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| Products connected (1).| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-03-05T00:21:01.436990Z",
                    "number": "17",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-05T00:25:01.236886Z",
                    "number": "18",
                    "summary": "Products connected (2).| Product Identifiers created (2)."
                },
                {
                    "date": "2026-03-05T00:25:05.915379Z",
                    "number": "19",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-05T21:06:00.291206Z",
                    "number": "20",
                    "summary": "Description removed for source.| Description created for source."
                },
                {
                    "date": "2026-03-06T00:21:02.891506Z",
                    "number": "21",
                    "summary": "Description removed for source.| Description created for source.| Products created (2).| Products removed (2)."
                },
                {
                    "date": "2026-03-20T10:15:58.806388Z",
                    "number": "22",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-20T10:16:01.648440Z",
                    "number": "23",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-24T20:54:23.521588Z",
                    "number": "24",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (2).| References created (3).| CWES updated (1).| Unknown change."
                },
                {
                    "date": "2026-03-24T20:54:33.734983Z",
                    "number": "25",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-25T15:25:03.795976Z",
                    "number": "26",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (2).| Product Identifiers created (2).| References created (5).| CWES updated (1)."
                },
                {
                    "date": "2026-03-25T15:25:11.831009Z",
                    "number": "27",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-25T15:39:48.793086Z",
                    "number": "28",
                    "summary": "Description removed for source.| Description created for source.| References created (3).| References removed (1)."
                },
                {
                    "date": "2026-03-25T16:25:31.734113Z",
                    "number": "29",
                    "summary": "CVSS updated."
                },
                {
                    "date": "2026-03-25T16:25:41.474241Z",
                    "number": "30",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-25T16:44:20.567884Z",
                    "number": "31",
                    "summary": "CVSS updated."
                },
                {
                    "date": "2026-03-26T06:45:01.319038Z",
                    "number": "32",
                    "summary": "Description removed for source.| Description created for source."
                },
                {
                    "date": "2026-03-28T21:47:50.438353Z",
                    "number": "33",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (9).| Product Identifiers created (6).| References created (5)."
                },
                {
                    "date": "2026-03-28T21:47:56.221510Z",
                    "number": "34",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-04-01T17:35:55.322855Z",
                    "number": "35",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-04-01T17:35:58.744691Z",
                    "number": "36",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-04-02T18:47:47.504599Z",
                    "number": "37",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (4).| References created (8).| CWES updated (1)."
                },
                {
                    "date": "2026-04-02T18:47:49.508981Z",
                    "number": "38",
                    "summary": "NCSC Score updated."
                }
            ],
            "status": "interim",
            "version": "38"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/4",
                                "product": {
                                    "name": "vers:rpm/4",
                                    "product_id": "CSAFPID-2552001",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:cryostat:4"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Cryostat 4"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/2",
                                "product": {
                                    "name": "vers:rpm/2",
                                    "product_id": "CSAFPID-1919968",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:migration_toolkit_virtualization:2"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Migration Toolkit for Virtualization"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/unknown",
                                "product": {
                                    "name": "vers:rpm/unknown",
                                    "product_id": "CSAFPID-1441056",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:multicluster_engine"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Multicluster Engine for Kubernetes"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/1",
                                "product": {
                                    "name": "vers:rpm/1",
                                    "product_id": "CSAFPID-2159488",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:network_observ_optr:1"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Network Observability Operator"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/0",
                                "product": {
                                    "name": "vers:rpm/0",
                                    "product_id": "CSAFPID-5222661",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:workload_availability_nhc:0"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Node HealthCheck Operator"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/1",
                                "product": {
                                    "name": "vers:rpm/1",
                                    "product_id": "CSAFPID-1919971",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:openshift_pipelines:1"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "OpenShift Pipelines"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/2",
                                "product": {
                                    "name": "vers:rpm/2",
                                    "product_id": "CSAFPID-1439310",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:red_hat_3scale_amp:2"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat 3scale API Management Platform 2"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/2",
                                "product": {
                                    "name": "vers:rpm/2",
                                    "product_id": "CSAFPID-1441080",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:acm:2"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Advanced Cluster Management for Kubernetes 2"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/4",
                                "product": {
                                    "name": "vers:rpm/4",
                                    "product_id": "CSAFPID-1441083",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:advanced_cluster_security:4"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Advanced Cluster Security 4"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/2",
                                "product": {
                                    "name": "vers:rpm/2",
                                    "product_id": "CSAFPID-1508257",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Ansible Automation Platform 2"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/10",
                                "product": {
                                    "name": "vers:rpm/10",
                                    "product_id": "CSAFPID-2858634",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:10"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 10"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/8",
                                "product": {
                                    "name": "vers:rpm/8",
                                    "product_id": "CSAFPID-1439317",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:enterprise_linux:8"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 8"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/9",
                                "product": {
                                    "name": "vers:rpm/9",
                                    "product_id": "CSAFPID-1439319",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:enterprise_linux:9"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 9"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/unknown",
                                "product": {
                                    "name": "vers:rpm/unknown",
                                    "product_id": "CSAFPID-1439279",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:openshift_ai"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat OpenShift AI (RHOAI)"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/4",
                                "product": {
                                    "name": "vers:rpm/4",
                                    "product_id": "CSAFPID-1439328",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:openshift:4"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat OpenShift Container Platform 4"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/1",
                                "product": {
                                    "name": "vers:rpm/1",
                                    "product_id": "CSAFPID-1439281",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:openshift_gitops:1"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat OpenShift GitOps"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/4",
                                "product": {
                                    "name": "vers:rpm/4",
                                    "product_id": "CSAFPID-1441162",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:container_native_virtualization:4"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat OpenShift Virtualization 4"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/4",
                                "product": {
                                    "name": "vers:rpm/4",
                                    "product_id": "CSAFPID-1441147",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:openshift_data_foundation:4"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Openshift Data Foundation 4"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/7",
                                "product": {
                                    "name": "vers:rpm/7",
                                    "product_id": "CSAFPID-1439306",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:jboss_enterprise_bpms_platform:7"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Process Automation 7"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/4",
                                "product": {
                                    "name": "vers:rpm/4",
                                    "product_id": "CSAFPID-2467441",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:apache_camel_hawtio:4"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat build of Apache Camel - HawtIO 4"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/2",
                                "product": {
                                    "name": "vers:rpm/2",
                                    "product_id": "CSAFPID-2467443",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:service_registry:2"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat build of Apicurio Registry 2"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/2",
                                "product": {
                                    "name": "vers:rpm/2",
                                    "product_id": "CSAFPID-5486263",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:ansible_portal:2"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Self-service automation portal 2"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1439282"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "argocd-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2847218"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "argocd-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2778184"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "console-plugin-rhel8"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat OpenShift GitOps"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1508264"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "automation-controller"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1837472"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "automation-eda-controller"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1837473"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "automation-gateway"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5222698"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "automation-platform-ui"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5172460"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "gateway-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Ansible Automation Platform 2"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5486265"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "automation-portal"
                            }
                        ],
                        "category": "product_family",
                        "name": "Self-service automation portal 2"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2467458"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "com.github.streamshub-console"
                            }
                        ],
                        "category": "product_family",
                        "name": "streams for Apache Kafka 2"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-3026118"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "com.github.streamshub-console"
                            }
                        ],
                        "category": "product_family",
                        "name": "streams for Apache Kafka 3"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2778177"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "console-mce-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Multicluster Engine for Kubernetes"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2109918"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "console-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Advanced Cluster Management for Kubernetes 2"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2868420"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "grafana"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 10"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1663145"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "grafana"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 8"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1496261"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "grafana"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 9"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2467444"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "io.apicurio-apicurio-registry"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat build of Apicurio Registry 2"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2698055"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "io.cryostat-cryostat"
                            }
                        ],
                        "category": "product_family",
                        "name": "Cryostat 4"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2467442"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "io.hawt-project"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat build of Apache Camel - HawtIO 4"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2778185"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "kubevirt-console-plugin"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2159497"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "kubevirt-console-plugin-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat OpenShift Virtualization 4"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2159487"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "mtv-console-plugin-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Migration Toolkit for Virtualization"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2985383"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "network-observability-console-plugin-compat-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Network Observability Operator"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-3086230"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "node-healthcheck-must-gather-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1496215"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "node-healthcheck-operator-bundle"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-3120253"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "node-healthcheck-rhel9-operator"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-3120254"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "node-remediation-console-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Node HealthCheck Operator"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2159494"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ocs-client-console-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2159495"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odf-console-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2159496"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odf-multicluster-console-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Openshift Data Foundation 4"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2933419"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-dashboard-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1441104"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-data-science-pipelines-argo-argoexec-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1441105"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-data-science-pipelines-argo-workflowcontroller-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5222758"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-mod-arch-gen-ai-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5157328"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-mod-arch-model-registry-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1441106"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-model-registry-rhel8"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat OpenShift AI (RHOAI)"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2159498"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "org.kie-process-migration-service"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Process Automation 7"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1441120"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ose-console"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2847216"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ose-console-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2159493"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ose-monitoring-plugin-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat OpenShift Container Platform 4"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2467435"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pipelines-hub-api-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2467436"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pipelines-hub-db-migration-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2467437"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pipelines-hub-ui-rhel8"
                            }
                        ],
                        "category": "product_family",
                        "name": "OpenShift Pipelines"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1441085"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "rhacs-main-rhel8"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Advanced Cluster Security 4"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/2",
                                "product": {
                                    "name": "vers:rpm/2",
                                    "product_id": "CSAFPID-2467457",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:amq_streams:2"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "streams for Apache Kafka 2"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/3",
                                "product": {
                                    "name": "vers:rpm/3",
                                    "product_id": "CSAFPID-3026117",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:amq_streams:3"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "streams for Apache Kafka 3"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5360337"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "system"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5360339"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "system-rhel7"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5360342"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "system-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5360344"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "system-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat 3scale API Management Platform 2"
                    }
                ],
                "category": "vendor",
                "name": "Red Hat"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=2.5.3|<2.5.9",
                                "product": {
                                    "name": "vers:unknown/>=2.5.3|<2.5.9",
                                    "product_id": "CSAFPID-5764093"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=2.5.3|<=2.5.8",
                                "product": {
                                    "name": "vers:unknown/>=2.5.3|<=2.5.8",
                                    "product_id": "CSAFPID-5759794",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:cure53:dompurify:*:*:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=3.1.3|<3.3.2",
                                "product": {
                                    "name": "vers:unknown/>=3.1.3|<3.3.2",
                                    "product_id": "CSAFPID-5764092"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=3.1.3|<=3.3.1",
                                "product": {
                                    "name": "vers:unknown/>=3.1.3|<=3.3.1",
                                    "product_id": "CSAFPID-5759795",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:cure53:dompurify:*:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "DOMPurify"
                    }
                ],
                "category": "vendor",
                "name": "Cure53"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/2.5.3|<=2.5.8",
                                "product": {
                                    "name": "vers:semver/2.5.3|<=2.5.8",
                                    "product_id": "CSAFPID-5757010"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/3.1.3|<=3.3.1",
                                "product": {
                                    "name": "vers:semver/3.1.3|<=3.3.1",
                                    "product_id": "CSAFPID-5757011"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "DOMPurify"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.5.9",
                                "product": {
                                    "name": "vers:unknown/2.5.9",
                                    "product_id": "CSAFPID-5985200"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.3.2",
                                "product": {
                                    "name": "vers:unknown/3.3.2",
                                    "product_id": "CSAFPID-5985199"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=2.5.3|<2.5.9",
                                "product": {
                                    "name": "vers:unknown/>=2.5.3|<2.5.9",
                                    "product_id": "CSAFPID-5985202"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=3.1.3|<3.3.2",
                                "product": {
                                    "name": "vers:unknown/>=3.1.3|<3.3.2",
                                    "product_id": "CSAFPID-5985201"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "npm/dompurify"
                    }
                ],
                "category": "vendor",
                "name": "cure53"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/unknown",
                                        "product": {
                                            "name": "vers:deb/unknown",
                                            "product_id": "CSAFPID-2100872"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "node-dompurify"
                            }
                        ],
                        "category": "product_family",
                        "name": "bookworm"
                    }
                ],
                "category": "vendor",
                "name": "Debian"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/2.3.0+dfsg-2",
                                        "product": {
                                            "name": "vers:unknown/2.3.0+dfsg-2",
                                            "product_id": "CSAFPID-5958895",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/node-dompurify@2.3.0%2Bdfsg-2?arch=source&distro=jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/2.3.3+dfsg-1",
                                        "product": {
                                            "name": "vers:unknown/2.3.3+dfsg-1",
                                            "product_id": "CSAFPID-5958896",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/node-dompurify@2.3.3%2Bdfsg-1?arch=source&distro=jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-5958897"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "node-dompurify"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:22.04:LTS"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/2.4.1+dfsg+~2.4.0-1",
                                        "product": {
                                            "name": "vers:unknown/2.4.1+dfsg+~2.4.0-1",
                                            "product_id": "CSAFPID-5958898",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/node-dompurify@2.4.1%2Bdfsg%2B~2.4.0-1?arch=source&distro=noble"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/3.0.9+dfsg+~3.0.5-1",
                                        "product": {
                                            "name": "vers:unknown/3.0.9+dfsg+~3.0.5-1",
                                            "product_id": "CSAFPID-5958899",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/node-dompurify@3.0.9%2Bdfsg%2B~3.0.5-1?arch=source&distro=noble"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-5958900"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "node-dompurify"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:24.04:LTS"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/3.1.7+dfsg+~3.0.5-1",
                                        "product": {
                                            "name": "vers:unknown/3.1.7+dfsg+~3.0.5-1",
                                            "product_id": "CSAFPID-5958901",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/node-dompurify@3.1.7%2Bdfsg%2B~3.0.5-1?arch=source&distro=questing"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/3.1.7+dfsg+~3.0.5-2",
                                        "product": {
                                            "name": "vers:unknown/3.1.7+dfsg+~3.0.5-2",
                                            "product_id": "CSAFPID-5958902",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/node-dompurify@3.1.7%2Bdfsg%2B~3.0.5-2?arch=source&distro=questing"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-5958903"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "node-dompurify"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:25.10"
                    }
                ],
                "category": "vendor",
                "name": "Ubuntu"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-0540",
            "cwe": {
                "id": "CWE-79",
                "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 729097f, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements (noscript, xmp, noembed, noframes, iframe) in the SAFE_FOR_XML regex. Attackers can include payloads like </noscript><img src=x onerror=alert(1)> in attribute values to execute JavaScript when sanitized output is placed inside these unprotected rawtext contexts.",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-0540"
                },
                {
                    "category": "description",
                    "text": "DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 729097f, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements (noscript, xmp, noembed, noframes, iframe) in the SAFE_FOR_XML regex. Attackers can include payloads like </noscript><img src=x onerror=alert(1)> in attribute values to execute JavaScript when sanitized output is placed inside these unprotected rawtext contexts.",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-0540"
                },
                {
                    "category": "description",
                    "text": "No description is available for this CVE.",
                    "title": "redhat - https://access.redhat.com/security/cve/CVE-2026-0540"
                },
                {
                    "category": "description",
                    "text": "DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in 2.5.9 and 3.3.2, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements (noscript, xmp, noembed, noframes, iframe) in the `SAFE_FOR_XML` regex. Attackers can include payloads like `</noscript><img src=x onerror=alert(1)>` in attribute values to execute JavaScript when sanitized output is placed inside these unprotected rawtext contexts.",
                    "title": "github - https://github.com/advisories/GHSA-v2wj-7wpq-c8vv"
                },
                {
                    "category": "description",
                    "text": "DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in 2.5.9 and 3.3.2, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements (noscript, xmp, noembed, noframes, iframe) in the `SAFE_FOR_XML` regex. Attackers can include payloads like `</noscript><img src=x onerror=alert(1)>` in attribute values to execute JavaScript when sanitized output is placed inside these unprotected rawtext contexts.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/npm%2FGHSA-v2wj-7wpq-c8vv.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 2726c74, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements (noscript, xmp, noembed, noframes, iframe) in the SAFE_FOR_XML regex. Attackers can include payloads like </noscript><img src=x onerror=alert(1)> in attribute values to execute JavaScript when sanitized output is placed inside these unprotected rawtext contexts.",
                    "title": "nvd - https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-0540"
                },
                {
                    "category": "description",
                    "text": "DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 2726c74, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements (noscript, xmp, noembed, noframes, iframe) in the SAFE_FOR_XML regex. Attackers can include payloads like </noscript><img src=x onerror=alert(1)> in attribute values to execute JavaScript when sanitized output is placed inside these unprotected rawtext contexts.",
                    "title": "cveprojectv5 - https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/0xxx/CVE-2026-0540.json"
                },
                {
                    "category": "description",
                    "text": "DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 2726c74, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements (noscript, xmp, noembed, noframes, iframe) in the SAFE_FOR_XML regex. Attackers can include payloads like </noscript><img src=x onerror=alert(1)> in attribute values to execute JavaScript when sanitized output is placed inside these unprotected rawtext contexts.",
                    "title": "debian - https://security-tracker.debian.org/tracker/CVE-2026-0540"
                },
                {
                    "category": "description",
                    "text": "DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 729097f, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements (noscript, xmp, noembed, noframes, iframe) in the SAFE_FOR_XML regex. Attackers can include payloads like </noscript><img src=x onerror=alert(1)> in attribute values to execute JavaScript when sanitized output is placed inside these unprotected rawtext contexts.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Ubuntu%2FUBUNTU-CVE-2026-0540.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in 2.5.9 and 3.3.2, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements (noscript, xmp, noembed, noframes, iframe) in the `SAFE_FOR_XML` regex. Attackers can include payloads like `</noscript><img src=x onerror=alert(1)>` in attribute values to execute JavaScript when sanitized output is placed inside these unprotected rawtext contexts.",
                    "title": "gitlab - https://gitlab.com/api/v4/projects/25847700/repository/files/npm%2Fdompurify%2FCVE-2026-0540.yml/raw"
                },
                {
                    "category": "other",
                    "text": "0.00012",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
                    "title": "CVSSV4"
                },
                {
                    "category": "other",
                    "text": "5.3",
                    "title": "CVSSV4 base score"
                },
                {
                    "category": "other",
                    "text": "4.3",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "Is related to (a version of) an uncommon product",
                    "title": "NCSC Score top increasing factors"
                },
                {
                    "category": "other",
                    "text": "Is related to a product by vendor Red Hat",
                    "title": "NCSC Score top decreasing factors"
                },
                {
                    "category": "details",
                    "text": "Severity: 2\n",
                    "title": "Vendor assessment"
                }
            ],
            "product_status": {
                "fixed": [
                    "CSAFPID-5985199",
                    "CSAFPID-5985200"
                ],
                "known_affected": [
                    "CSAFPID-5757010",
                    "CSAFPID-5757011",
                    "CSAFPID-2100872",
                    "CSAFPID-1439279",
                    "CSAFPID-1439281",
                    "CSAFPID-1439282",
                    "CSAFPID-1439306",
                    "CSAFPID-1439310",
                    "CSAFPID-1439317",
                    "CSAFPID-1439319",
                    "CSAFPID-1439328",
                    "CSAFPID-1441056",
                    "CSAFPID-1441080",
                    "CSAFPID-1441083",
                    "CSAFPID-1441085",
                    "CSAFPID-1441104",
                    "CSAFPID-1441105",
                    "CSAFPID-1441106",
                    "CSAFPID-1441120",
                    "CSAFPID-1441147",
                    "CSAFPID-1441162",
                    "CSAFPID-1496215",
                    "CSAFPID-1496261",
                    "CSAFPID-1508257",
                    "CSAFPID-1508264",
                    "CSAFPID-1663145",
                    "CSAFPID-1837472",
                    "CSAFPID-1837473",
                    "CSAFPID-1919968",
                    "CSAFPID-1919971",
                    "CSAFPID-2109918",
                    "CSAFPID-2159487",
                    "CSAFPID-2159488",
                    "CSAFPID-2159493",
                    "CSAFPID-2159494",
                    "CSAFPID-2159495",
                    "CSAFPID-2159496",
                    "CSAFPID-2159497",
                    "CSAFPID-2159498",
                    "CSAFPID-2467435",
                    "CSAFPID-2467436",
                    "CSAFPID-2467437",
                    "CSAFPID-2467441",
                    "CSAFPID-2467442",
                    "CSAFPID-2467443",
                    "CSAFPID-2467444",
                    "CSAFPID-2467457",
                    "CSAFPID-2467458",
                    "CSAFPID-2552001",
                    "CSAFPID-2698055",
                    "CSAFPID-2778177",
                    "CSAFPID-2778184",
                    "CSAFPID-2778185",
                    "CSAFPID-2847216",
                    "CSAFPID-2847218",
                    "CSAFPID-2858634",
                    "CSAFPID-2868420",
                    "CSAFPID-2933419",
                    "CSAFPID-2985383",
                    "CSAFPID-3026117",
                    "CSAFPID-3026118",
                    "CSAFPID-3086230",
                    "CSAFPID-3120253",
                    "CSAFPID-3120254",
                    "CSAFPID-5157328",
                    "CSAFPID-5172460",
                    "CSAFPID-5222661",
                    "CSAFPID-5222698",
                    "CSAFPID-5222758",
                    "CSAFPID-5360337",
                    "CSAFPID-5360339",
                    "CSAFPID-5360342",
                    "CSAFPID-5360344",
                    "CSAFPID-5486263",
                    "CSAFPID-5486265",
                    "CSAFPID-5759794",
                    "CSAFPID-5759795",
                    "CSAFPID-5764092",
                    "CSAFPID-5764093",
                    "CSAFPID-5958895",
                    "CSAFPID-5958896",
                    "CSAFPID-5958897",
                    "CSAFPID-5958898",
                    "CSAFPID-5958899",
                    "CSAFPID-5958900",
                    "CSAFPID-5958901",
                    "CSAFPID-5958902",
                    "CSAFPID-5958903",
                    "CSAFPID-5985201",
                    "CSAFPID-5985202"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-0540"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/0xxx/CVE-2026-0540.json"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0540"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-0540"
                },
                {
                    "category": "external",
                    "summary": "Source - debian",
                    "url": "https://security-tracker.debian.org/tracker/CVE-2026-0540"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-0540"
                },
                {
                    "category": "external",
                    "summary": "Source raw - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-0540.json"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-0540"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://github.com/advisories/GHSA-v2wj-7wpq-c8vv"
                },
                {
                    "category": "external",
                    "summary": "Source raw - github",
                    "url": "https://api.github.com/advisories/GHSA-v2wj-7wpq-c8vv"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/npm%2FGHSA-v2wj-7wpq-c8vv.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/0xxx/CVE-2026-0540.json"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-0540"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Ubuntu%2FUBUNTU-CVE-2026-0540.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=10000"
                },
                {
                    "category": "external",
                    "summary": "Source - gitlab",
                    "url": "https://gitlab.com/api/v4/projects/25847700/repository/files/npm%2Fdompurify%2FCVE-2026-0540.yml/raw"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; gitlab; nvd; osv; redhat",
                    "url": "https://github.com/cure53/DOMPurify"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; gitlab; nvd; osv; redhat",
                    "url": "https://github.com/cure53/DOMPurify/commit/fca0a938b4261ddc9c0293a289935a9029c049f5"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; gitlab; nvd; osv",
                    "url": "https://www.vulncheck.com/advisories/dompurify-xss-via-missing-rawtext-elements-in-safe-for-xml"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv; redhat",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-0540"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; gitlab; osv; redhat",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0540"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv; redhat",
                    "url": "https://www.vulncheck.com/advisories/dompurify-xss-via-missing-rawtext-elements-in-safeforxml"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; gitlab",
                    "url": "https://github.com/advisories/GHSA-v2wj-7wpq-c8vv"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; gitlab; nvd",
                    "url": "https://fluidattacks.com/advisories/daft"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; gitlab; nvd",
                    "url": "https://github.com/cure53/DOMPurify/commit/302b51de22535cc90235472c52e3401bedd46f80"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; gitlab; nvd",
                    "url": "https://github.com/cure53/DOMPurify/releases/tag/3.3.2"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://ubuntu.com/security/CVE-2026-0540"
                }
            ],
            "remediations": [
                {
                    "category": "mitigation",
                    "details": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
                    "product_ids": [
                        "CSAFPID-1439279",
                        "CSAFPID-1439281",
                        "CSAFPID-1439282",
                        "CSAFPID-1439306",
                        "CSAFPID-1439310",
                        "CSAFPID-1439317",
                        "CSAFPID-1439319",
                        "CSAFPID-1439328",
                        "CSAFPID-1441056",
                        "CSAFPID-1441080",
                        "CSAFPID-1441083",
                        "CSAFPID-1441085",
                        "CSAFPID-1441104",
                        "CSAFPID-1441105",
                        "CSAFPID-1441106",
                        "CSAFPID-1441120",
                        "CSAFPID-1441147",
                        "CSAFPID-1441162",
                        "CSAFPID-1496215",
                        "CSAFPID-1496261",
                        "CSAFPID-1508257",
                        "CSAFPID-1508264",
                        "CSAFPID-1663145",
                        "CSAFPID-1837472",
                        "CSAFPID-1837473",
                        "CSAFPID-1919968",
                        "CSAFPID-1919971",
                        "CSAFPID-2109918",
                        "CSAFPID-2159487",
                        "CSAFPID-2159488",
                        "CSAFPID-2159493",
                        "CSAFPID-2159494",
                        "CSAFPID-2159495",
                        "CSAFPID-2159496",
                        "CSAFPID-2159497",
                        "CSAFPID-2159498",
                        "CSAFPID-2467435",
                        "CSAFPID-2467436",
                        "CSAFPID-2467437",
                        "CSAFPID-2467441",
                        "CSAFPID-2467442",
                        "CSAFPID-2467443",
                        "CSAFPID-2467444",
                        "CSAFPID-2467457",
                        "CSAFPID-2467458",
                        "CSAFPID-2552001",
                        "CSAFPID-2698055",
                        "CSAFPID-2778177",
                        "CSAFPID-2778184",
                        "CSAFPID-2778185",
                        "CSAFPID-2847216",
                        "CSAFPID-2847218",
                        "CSAFPID-2858634",
                        "CSAFPID-2868420",
                        "CSAFPID-2933419",
                        "CSAFPID-2985383",
                        "CSAFPID-3026117",
                        "CSAFPID-3026118",
                        "CSAFPID-3086230",
                        "CSAFPID-3120253",
                        "CSAFPID-3120254",
                        "CSAFPID-5157328",
                        "CSAFPID-5172460",
                        "CSAFPID-5222661",
                        "CSAFPID-5222698",
                        "CSAFPID-5222758",
                        "CSAFPID-5360337",
                        "CSAFPID-5360339",
                        "CSAFPID-5360342",
                        "CSAFPID-5360344",
                        "CSAFPID-5486263",
                        "CSAFPID-5486265"
                    ]
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                        "baseScore": 6.1,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-1439279",
                        "CSAFPID-1439281",
                        "CSAFPID-1439282",
                        "CSAFPID-1439306",
                        "CSAFPID-1439310",
                        "CSAFPID-1439317",
                        "CSAFPID-1439319",
                        "CSAFPID-1439328",
                        "CSAFPID-1441056",
                        "CSAFPID-1441080",
                        "CSAFPID-1441083",
                        "CSAFPID-1441085",
                        "CSAFPID-1441104",
                        "CSAFPID-1441105",
                        "CSAFPID-1441106",
                        "CSAFPID-1441120",
                        "CSAFPID-1441147",
                        "CSAFPID-1441162",
                        "CSAFPID-1496215",
                        "CSAFPID-1496261",
                        "CSAFPID-1508257",
                        "CSAFPID-1508264",
                        "CSAFPID-1663145",
                        "CSAFPID-1837472",
                        "CSAFPID-1837473",
                        "CSAFPID-1919968",
                        "CSAFPID-1919971",
                        "CSAFPID-2100872",
                        "CSAFPID-2109918",
                        "CSAFPID-2159487",
                        "CSAFPID-2159488",
                        "CSAFPID-2159493",
                        "CSAFPID-2159494",
                        "CSAFPID-2159495",
                        "CSAFPID-2159496",
                        "CSAFPID-2159497",
                        "CSAFPID-2159498",
                        "CSAFPID-2467435",
                        "CSAFPID-2467436",
                        "CSAFPID-2467437",
                        "CSAFPID-2467441",
                        "CSAFPID-2467442",
                        "CSAFPID-2467443",
                        "CSAFPID-2467444",
                        "CSAFPID-2467457",
                        "CSAFPID-2467458",
                        "CSAFPID-2552001",
                        "CSAFPID-2698055",
                        "CSAFPID-2778177",
                        "CSAFPID-2778184",
                        "CSAFPID-2778185",
                        "CSAFPID-2847216",
                        "CSAFPID-2847218",
                        "CSAFPID-2858634",
                        "CSAFPID-2868420",
                        "CSAFPID-2933419",
                        "CSAFPID-2985383",
                        "CSAFPID-3026117",
                        "CSAFPID-3026118",
                        "CSAFPID-3086230",
                        "CSAFPID-3120253",
                        "CSAFPID-3120254",
                        "CSAFPID-5157328",
                        "CSAFPID-5172460",
                        "CSAFPID-5222661",
                        "CSAFPID-5222698",
                        "CSAFPID-5222758",
                        "CSAFPID-5360337",
                        "CSAFPID-5360339",
                        "CSAFPID-5360342",
                        "CSAFPID-5360344",
                        "CSAFPID-5486263",
                        "CSAFPID-5486265",
                        "CSAFPID-5757010",
                        "CSAFPID-5757011",
                        "CSAFPID-5759794",
                        "CSAFPID-5759795",
                        "CSAFPID-5764092",
                        "CSAFPID-5764093",
                        "CSAFPID-5958895",
                        "CSAFPID-5958896",
                        "CSAFPID-5958897",
                        "CSAFPID-5958898",
                        "CSAFPID-5958899",
                        "CSAFPID-5958900",
                        "CSAFPID-5958901",
                        "CSAFPID-5958902",
                        "CSAFPID-5958903",
                        "CSAFPID-5985201",
                        "CSAFPID-5985202"
                    ]
                }
            ],
            "title": "CVE-2026-0540"
        }
    ]
}