{
  "@id": "urn:uuid:119df591-8223-47d4-8507-78138d10c74f",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/react-router-dom@6.30.4",
          "identifiers": {
            "purl": "pkg:npm/react-router-dom@6.30.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-43864 does not affect version 6.30.4 of react-router-dom. React Router v6.30.4 is not affected by CVE-2025-43864. The vulnerability is specific to React Router v7's Framework mode, which introduces server-runtime code that processes the X-React-Router-SPA-Mode header. v6.30.4 does not contain Framework mode, the server-runtime directory, or any code that processes this header. While v6 has SSR support via createStaticHandler, it uses traditional SSR where developers control the server, and there is no mechanism to force a SPA mode switch via request headers.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-43864"
      },
      "impact_statement": "React Router v6.30.4 is not affected by CVE-2025-43864. The vulnerability is specific to React Router v7's Framework mode, which introduces server-runtime code that processes the X-React-Router-SPA-Mode header. v6.30.4 does not contain Framework mode, the server-runtime directory, or any code that processes this header. While v6 has SSR support via createStaticHandler, it uses traditional SSR where developers control the server, and there is no mechanism to force a SPA mode switch via request headers."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/react-router-dom@6.30.4",
          "identifiers": {
            "purl": "pkg:npm/react-router-dom@6.30.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-43865 does not affect version 6.30.4 of react-router-dom. React Router v6.30.4 is NOT AFFECTED by CVE-2025-43865. The vulnerability requires server-runtime infrastructure and Framework mode functionality that was introduced in React Router v7.x. Version 6.30.4 is a client-side routing library that lacks the entire server-runtime codebase where the vulnerable header processing occurs. The vulnerable headers (X-React-Router-Prerender-Data, X-React-Router-SPA-Mode) are not processed anywhere in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-43865"
      },
      "impact_statement": "React Router v6.30.4 is NOT AFFECTED by CVE-2025-43865. The vulnerability requires server-runtime infrastructure and Framework mode functionality that was introduced in React Router v7.x. Version 6.30.4 is a client-side routing library that lacks the entire server-runtime codebase where the vulnerable header processing occurs. The vulnerable headers (X-React-Router-Prerender-Data, X-React-Router-SPA-Mode) are not processed anywhere in this version."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/react-router-dom@6.30.4",
          "identifiers": {
            "purl": "pkg:npm/react-router-dom@6.30.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59057 does not affect version 6.30.4 of react-router-dom. The target repository (react-router v6.30.4 at SHA 1fcae42c8) does not contain the vulnerable Framework Mode functionality described in CVE-2025-59057. The vulnerability affects React Router's meta()/Meta APIs in Framework Mode when generating script:ld+json tags, where unescaped HTML characters in JSON-LD content can enable XSS attacks. However, Framework Mode with its SSR components (lib/dom/ssr/) was introduced in React Router v7+, after version 6.30.4. The target version only supports Declarative Mode (BrowserRouter) and Data Mode (createBrowserRouter/RouterProvider), which the CVE explicitly states are not impacted. Exhaustive searches found no meta() function, no Meta component export, no script:ld+json generation, and no lib/dom/ssr/ directory in the target codebase.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-59057"
      },
      "impact_statement": "The target repository (react-router v6.30.4 at SHA 1fcae42c8) does not contain the vulnerable Framework Mode functionality described in CVE-2025-59057. The vulnerability affects React Router's meta()/Meta APIs in Framework Mode when generating script:ld+json tags, where unescaped HTML characters in JSON-LD content can enable XSS attacks. However, Framework Mode with its SSR components (lib/dom/ssr/) was introduced in React Router v7+, after version 6.30.4. The target version only supports Declarative Mode (BrowserRouter) and Data Mode (createBrowserRouter/RouterProvider), which the CVE explicitly states are not impacted. Exhaustive searches found no meta() function, no Meta component export, no script:ld+json generation, and no lib/dom/ssr/ directory in the target codebase."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/react-router-dom@6.30.4",
          "identifiers": {
            "purl": "pkg:npm/react-router-dom@6.30.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22029 does not affect version 6.30.4 of react-router-dom. The target repository (react-router v6.30.4, @remix-run/router v1.23.3) already contains the upstream vendor fix for CVE-2026-22029. The vulnerable code pattern is not present because the normalizeRedirectLocation function includes protocol validation that blocks dangerous protocols (javascript:, data:, blob:, file:, etc.). The fix was authored by Matt Brophy (matt@brophy.org), the upstream React Router maintainer, not TuxCare. The @remix-run/router version (1.23.3) is >= 1.23.2, which is the fixed version according to the CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-22029"
      },
      "impact_statement": "The target repository (react-router v6.30.4, @remix-run/router v1.23.3) already contains the upstream vendor fix for CVE-2026-22029. The vulnerable code pattern is not present because the normalizeRedirectLocation function includes protocol validation that blocks dangerous protocols (javascript:, data:, blob:, file:, etc.). The fix was authored by Matt Brophy (matt@brophy.org), the upstream React Router maintainer, not TuxCare. The @remix-run/router version (1.23.3) is >= 1.23.2, which is the fixed version according to the CVE."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/react-router-dom@6.30.4",
          "identifiers": {
            "purl": "pkg:npm/react-router-dom@6.30.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22030 affects version 6.30.4 of react-router-dom.",
      "vulnerability": {
        "name": "CVE-2026-22030"
      },
      "action_statement": "Vulnerability CVE-2026-22030 affects version 6.30.4 of react-router-dom."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/react-router-dom@6.30.4",
          "identifiers": {
            "purl": "pkg:npm/react-router-dom@6.30.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42211 does not affect version 6.30.4 of react-router-dom. React Router v6.30.4 is not affected by CVE-2026-42211. The vulnerability requires the turbo-stream vendor library and Framework Mode SSR capabilities, neither of which exist in v6.30.4. The vulnerable error deserialization code with unsafe global constructor lookup was introduced in later versions (v6.30.6+ and v7.x). This version only contains client-side routing functionality and has no code path that receives or processes serialized error objects in turbo-stream format.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-42211"
      },
      "impact_statement": "React Router v6.30.4 is not affected by CVE-2026-42211. The vulnerability requires the turbo-stream vendor library and Framework Mode SSR capabilities, neither of which exist in v6.30.4. The vulnerable error deserialization code with unsafe global constructor lookup was introduced in later versions (v6.30.6+ and v7.x). This version only contains client-side routing functionality and has no code path that receives or processes serialized error objects in turbo-stream format."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/react-router-dom@6.30.4",
          "identifiers": {
            "purl": "pkg:npm/react-router-dom@6.30.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53666 affects version 6.30.4 of react-router-dom, and is fixed in 6.30.4-tuxcare.1.",
      "vulnerability": {
        "name": "CVE-2026-53666"
      },
      "action_statement": "Vulnerability CVE-2026-53666 affects version 6.30.4 of react-router-dom, and is fixed in 6.30.4-tuxcare.1."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/react-router-dom@6.30.4",
          "identifiers": {
            "purl": "pkg:npm/react-router-dom@6.30.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53668 affects version 6.30.4 of react-router-dom, and is fixed in 6.30.4-tuxcare.1.",
      "vulnerability": {
        "name": "CVE-2026-53668"
      },
      "action_statement": "Vulnerability CVE-2026-53668 affects version 6.30.4 of react-router-dom, and is fixed in 6.30.4-tuxcare.1."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/react-router-dom@6.30.4",
          "identifiers": {
            "purl": "pkg:npm/react-router-dom@6.30.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53669 affects version 6.30.4 of react-router-dom, and is fixed in 6.30.4-tuxcare.1.",
      "vulnerability": {
        "name": "CVE-2026-53669"
      },
      "action_statement": "Vulnerability CVE-2026-53669 affects version 6.30.4 of react-router-dom, and is fixed in 6.30.4-tuxcare.1."
    }
  ]
}
