{
  "@id": "urn:uuid:46f4f1f6-e976-4fd3-b79d-94b34fae612d",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/react-router-dom@6.30.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/react-router-dom@6.30.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-43864 does not affect version 6.30.3-tuxcare.1 of react-router-dom. React Router v6.30.3 is not affected by CVE-2025-43864. The vulnerability exists only in React Router v7's Framework mode, which introduced the createRequestHandler function that processes X-React-Router-SPA-Mode and X-React-Router-Prerender-Data headers to control rendering modes. Version 6.30.3 does not have Framework mode, does not have the server-runtime module structure, and does not process these headers anywhere in the codebase. The vulnerable code path was introduced in v7 and fixed in v7.6.2 (commit c84302972).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-43864"
      },
      "impact_statement": "React Router v6.30.3 is not affected by CVE-2025-43864. The vulnerability exists only in React Router v7's Framework mode, which introduced the createRequestHandler function that processes X-React-Router-SPA-Mode and X-React-Router-Prerender-Data headers to control rendering modes. Version 6.30.3 does not have Framework mode, does not have the server-runtime module structure, and does not process these headers anywhere in the codebase. The vulnerable code path was introduced in v7 and fixed in v7.6.2 (commit c84302972)."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/react-router-dom@6.30.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/react-router-dom@6.30.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-43865 does not affect version 6.30.3-tuxcare.1 of react-router-dom. React Router v6.30.3 is not affected by CVE-2025-43865. The vulnerability exists in React Router v7.x Framework mode's server-runtime code that processes the X-React-Router-Prerender-Data header to override prerendered data. Version 6.30.3 predates Framework mode entirely and does not contain the vulnerable server-runtime module (packages/react-router/lib/server-runtime/*) introduced in v7.x. No code path exists in v6.30.3 that would process these build-time headers, preventing the attack chain from Input (malicious headers) to Goal (data override).",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2025-43865"
      },
      "impact_statement": "React Router v6.30.3 is not affected by CVE-2025-43865. The vulnerability exists in React Router v7.x Framework mode's server-runtime code that processes the X-React-Router-Prerender-Data header to override prerendered data. Version 6.30.3 predates Framework mode entirely and does not contain the vulnerable server-runtime module (packages/react-router/lib/server-runtime/*) introduced in v7.x. No code path exists in v6.30.3 that would process these build-time headers, preventing the attack chain from Input (malicious headers) to Goal (data override)."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/react-router-dom@6.30.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/react-router-dom@6.30.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59057 does not affect version 6.30.3-tuxcare.1 of react-router-dom. React Router 6.30.3 is not affected by CVE-2025-59057. The vulnerability exists in Framework Mode's `meta()` API and `<Meta>` component when generating JSON-LD script tags, but these features do not exist in version 6.30.3. Framework Mode was introduced in React Router 7.x. Version 6.30.3 uses only Declarative Mode (<BrowserRouter>) and Data Mode (createBrowserRouter/<RouterProvider>), which the CVE explicitly states are not impacted. Exhaustive searches confirmed no Meta component, no meta() function, no MetaFunction types, and no application/ld+json script tag generation in the codebase. The only dangerouslySetInnerHTML usage (hydration script in server.tsx) already uses htmlEscape() protection.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-59057"
      },
      "impact_statement": "React Router 6.30.3 is not affected by CVE-2025-59057. The vulnerability exists in Framework Mode's `meta()` API and `<Meta>` component when generating JSON-LD script tags, but these features do not exist in version 6.30.3. Framework Mode was introduced in React Router 7.x. Version 6.30.3 uses only Declarative Mode (<BrowserRouter>) and Data Mode (createBrowserRouter/<RouterProvider>), which the CVE explicitly states are not impacted. Exhaustive searches confirmed no Meta component, no meta() function, no MetaFunction types, and no application/ld+json script tag generation in the codebase. The only dangerouslySetInnerHTML usage (hydration script in server.tsx) already uses htmlEscape() protection."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/react-router-dom@6.30.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/react-router-dom@6.30.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22029 does not affect version 6.30.3-tuxcare.1 of react-router-dom. The target (React Router v6.30.3) is not affected by CVE-2026-22029. The vulnerability concerning unsafe redirect protocols leading to JavaScript execution has been addressed by an upstream vendor fix already present in the codebase. The fix validates redirect locations against unsafe protocols (javascript:, data:, about:, blob:, file:, filesystem:, chrome:, devtools:, content:, chrome-untrusted:) and throws errors before processing redirects from loaders/actions.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-22029"
      },
      "impact_statement": "The target (React Router v6.30.3) is not affected by CVE-2026-22029. The vulnerability concerning unsafe redirect protocols leading to JavaScript execution has been addressed by an upstream vendor fix already present in the codebase. The fix validates redirect locations against unsafe protocols (javascript:, data:, about:, blob:, file:, filesystem:, chrome:, devtools:, content:, chrome-untrusted:) and throws errors before processing redirects from loaders/actions."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/react-router-dom@6.30.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/react-router-dom@6.30.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22030 affects version 6.30.3-tuxcare.1 of react-router-dom.",
      "vulnerability": {
        "name": "CVE-2026-22030"
      },
      "action_statement": "Vulnerability CVE-2026-22030 affects version 6.30.3-tuxcare.1 of react-router-dom."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/react-router-dom@6.30.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/react-router-dom@6.30.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40181 is fixed in version 6.30.3-tuxcare.1 of react-router-dom.",
      "vulnerability": {
        "name": "CVE-2026-40181"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/react-router-dom@6.30.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/react-router-dom@6.30.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42211 affects version 6.30.3-tuxcare.1 of react-router-dom.",
      "vulnerability": {
        "name": "CVE-2026-42211"
      },
      "action_statement": "Vulnerability CVE-2026-42211 affects version 6.30.3-tuxcare.1 of react-router-dom."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/react-router-dom@6.30.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/react-router-dom@6.30.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53666 affects version 6.30.3-tuxcare.1 of react-router-dom, and is fixed in 6.30.3-tuxcare.2.",
      "vulnerability": {
        "name": "CVE-2026-53666"
      },
      "action_statement": "Vulnerability CVE-2026-53666 affects version 6.30.3-tuxcare.1 of react-router-dom, and is fixed in 6.30.3-tuxcare.2."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/react-router-dom@6.30.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/react-router-dom@6.30.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53668 is fixed in version 6.30.3-tuxcare.1 of react-router-dom.",
      "vulnerability": {
        "name": "CVE-2026-53668"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/react-router-dom@6.30.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/react-router-dom@6.30.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53669 affects version 6.30.3-tuxcare.1 of react-router-dom, and is fixed in 6.30.3-tuxcare.3.",
      "vulnerability": {
        "name": "CVE-2026-53669"
      },
      "action_statement": "Vulnerability CVE-2026-53669 affects version 6.30.3-tuxcare.1 of react-router-dom, and is fixed in 6.30.3-tuxcare.3."
    }
  ]
}
