{
  "@id": "urn:uuid:66e3cbba-959c-4faa-8b37-5e76d7228f67",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/react-router-native@6.30.6-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/react-router-native@6.30.6-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-43864 does not affect version 6.30.6-tuxcare.1 of react-router-native. React Router v6.30.6 is not affected by CVE-2025-43864. This vulnerability requires React Router v7's Framework mode, which introduces server-side rendering with build-time/runtime distinction and the ability to control rendering modes via HTTP headers. The vulnerable code pattern\u2014reading `X-React-Router-SPA-Mode` or `X-React-Router-Prerender-Data` headers to alter rendering behavior\u2014does not exist in v6. Version 6 is a client-side routing library with basic SSR support via StaticHandler, but lacks the Framework mode architecture where this vulnerability manifests. The entire `server-runtime` module and `react-router-dev` package are absent from v6. No code in v6 reads the vulnerable headers or implements mode-switching behavior based on request headers.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-43864"
      },
      "impact_statement": "React Router v6.30.6 is not affected by CVE-2025-43864. This vulnerability requires React Router v7's Framework mode, which introduces server-side rendering with build-time/runtime distinction and the ability to control rendering modes via HTTP headers. The vulnerable code pattern\u2014reading `X-React-Router-SPA-Mode` or `X-React-Router-Prerender-Data` headers to alter rendering behavior\u2014does not exist in v6. Version 6 is a client-side routing library with basic SSR support via StaticHandler, but lacks the Framework mode architecture where this vulnerability manifests. The entire `server-runtime` module and `react-router-dev` package are absent from v6. No code in v6 reads the vulnerable headers or implements mode-switching behavior based on request headers."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/react-router-native@6.30.6-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/react-router-native@6.30.6-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-43865 does not affect version 6.30.6-tuxcare.1 of react-router-native. The target repository is React Router v6.30.6, which is not affected by CVE-2025-43865. This vulnerability only exists in React Router v7.x \"Framework mode\" which introduced server-side rendering with special build-time headers (`X-React-Router-Prerender-Data` and `X-React-Router-SPA-Mode`). Version 6.30.6 is a client-side routing library that does not process these headers, lacks the server-runtime components (`lib/server-runtime/`), and does not have Framework mode capabilities. The vulnerable code path does not exist in v6.x. Rule 5 Type A1 applies: the INPUT type (the specific prerender headers) is not received anywhere in the target codebase.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-43865"
      },
      "impact_statement": "The target repository is React Router v6.30.6, which is not affected by CVE-2025-43865. This vulnerability only exists in React Router v7.x \"Framework mode\" which introduced server-side rendering with special build-time headers (`X-React-Router-Prerender-Data` and `X-React-Router-SPA-Mode`). Version 6.30.6 is a client-side routing library that does not process these headers, lacks the server-runtime components (`lib/server-runtime/`), and does not have Framework mode capabilities. The vulnerable code path does not exist in v6.x. Rule 5 Type A1 applies: the INPUT type (the specific prerender headers) is not received anywhere in the target codebase."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/react-router-native@6.30.6-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/react-router-native@6.30.6-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59057 does not affect version 6.30.6-tuxcare.1 of react-router-native. The target repository (React Router v6.30.6) is NOT AFFECTED by CVE-2025-59057. The vulnerability exists only in Framework Mode's `meta()`/`<Meta>` APIs when generating `script:ld+json` tags. Framework Mode was introduced in React Router v7 and does not exist in v6.30.6. The target only contains Declarative Mode (`<BrowserRouter>`) and Data Mode (`createBrowserRouter`/`RouterProvider`) components, which the CVE explicitly states are not impacted. Exhaustive searches confirm no `Meta` component, no `application/ld+json` handling, no SSR components, and no Framework Mode code exists in the target version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-59057"
      },
      "impact_statement": "The target repository (React Router v6.30.6) is NOT AFFECTED by CVE-2025-59057. The vulnerability exists only in Framework Mode's `meta()`/`<Meta>` APIs when generating `script:ld+json` tags. Framework Mode was introduced in React Router v7 and does not exist in v6.30.6. The target only contains Declarative Mode (`<BrowserRouter>`) and Data Mode (`createBrowserRouter`/`RouterProvider`) components, which the CVE explicitly states are not impacted. Exhaustive searches confirm no `Meta` component, no `application/ld+json` handling, no SSR components, and no Framework Mode code exists in the target version."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/react-router-native@6.30.6-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/react-router-native@6.30.6-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22029 does not affect version 6.30.6-tuxcare.1 of react-router-native. The target repository (react-router 6.30.6, @remix-run/router 1.23.4) is not affected by CVE-2026-22029. The upstream vendor fix was applied in commit 2fbb84c83 on 2026-01-06, more than 7 months before the 6.30.6 release on 2026-08-18. The vulnerable code pattern (unsafe redirect URLs allowing JavaScript execution) is not present because the normalizeRedirectLocation function includes protocol validation that rejects dangerous protocols (javascript:, data:, about:, blob:, file:, etc.).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-22029"
      },
      "impact_statement": "The target repository (react-router 6.30.6, @remix-run/router 1.23.4) is not affected by CVE-2026-22029. The upstream vendor fix was applied in commit 2fbb84c83 on 2026-01-06, more than 7 months before the 6.30.6 release on 2026-08-18. The vulnerable code pattern (unsafe redirect URLs allowing JavaScript execution) is not present because the normalizeRedirectLocation function includes protocol validation that rejects dangerous protocols (javascript:, data:, about:, blob:, file:, etc.)."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/react-router-native@6.30.6-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/react-router-native@6.30.6-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22030 does not affect version 6.30.6-tuxcare.1 of react-router-native. not_affected \u2014 React Router v6.30.6 is not affected by CVE-2026-22030. This version lacks the server-side runtime code that the vulnerability targets. The CVE explicitly affects \"server-side route action handlers in Framework Mode\" and \"React Server Actions in RSC modes\" - features introduced in React Router v7+. Version 6.30.6 only supports Declarative Mode (BrowserRouter) and Data Mode (createBrowserRouter)...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-22030"
      },
      "impact_statement": "not_affected \u2014 React Router v6.30.6 is not affected by CVE-2026-22030. This version lacks the server-side runtime code that the vulnerability targets. The CVE explicitly affects \"server-side route action handlers in Framework Mode\" and \"React Server Actions in RSC modes\" - features introduced in React Router v7+. Version 6.30.6 only supports Declarative Mode (BrowserRouter) and Data Mode (createBrowserRouter)..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/react-router-native@6.30.6-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/react-router-native@6.30.6-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42211 does not affect version 6.30.6-tuxcare.1 of react-router-native. React Router v6.30.6 is not affected by CVE-2026-42211. This vulnerability specifically affects React Router v7 in Framework Mode through unsafe error deserialization in the turbo-stream implementation. The target version (6.30.6) does not contain the vulnerable code - the turbo-stream error deserialization subsystem, single-fetch functionality, and Framework Mode are all v7-exclusive features that were introduced after v6. The vulnerable file `packages/react-router/lib/dom/ssr/single-fetch.tsx` and the entire vendor/turbo-stream-v2 directory do not exist in version 6.30.6.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-42211"
      },
      "impact_statement": "React Router v6.30.6 is not affected by CVE-2026-42211. This vulnerability specifically affects React Router v7 in Framework Mode through unsafe error deserialization in the turbo-stream implementation. The target version (6.30.6) does not contain the vulnerable code - the turbo-stream error deserialization subsystem, single-fetch functionality, and Framework Mode are all v7-exclusive features that were introduced after v6. The vulnerable file `packages/react-router/lib/dom/ssr/single-fetch.tsx` and the entire vendor/turbo-stream-v2 directory do not exist in version 6.30.6."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/react-router-native@6.30.6-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/react-router-native@6.30.6-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53666 is fixed in version 6.30.6-tuxcare.1 of react-router-native.",
      "vulnerability": {
        "name": "CVE-2026-53666"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/react-router-native@6.30.6-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/react-router-native@6.30.6-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53669 is fixed in version 6.30.6-tuxcare.1 of react-router-native.",
      "vulnerability": {
        "name": "CVE-2026-53669"
      }
    }
  ]
}
