{
  "@id": "urn:uuid:fde68f39-83fd-450b-ab98-96725955383d",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/react-router@6.3.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/react-router@6.3.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-43864 does not affect version 6.3.0-tuxcare.2 of react-router. not_affected \u2014 React Router v6.3.0-tuxcare.1 is not affected by CVE-2025-43864. The vulnerability is specific to React Router v7.x's server-side request handling and prerendering features, which do not exist in v6.3.0. The target version is a client-side routing library that does not process HTTP request headers.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-43864"
      },
      "impact_statement": "not_affected \u2014 React Router v6.3.0-tuxcare.1 is not affected by CVE-2025-43864. The vulnerability is specific to React Router v7.x's server-side request handling and prerendering features, which do not exist in v6.3.0. The target version is a client-side routing library that does not process HTTP request headers."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/react-router@6.3.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/react-router@6.3.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-43865 does not affect version 6.3.0-tuxcare.2 of react-router. not_affected \u2014 Version 6.3.0 is NOT AFFECTED by CVE-2025-43865. The vulnerability requires the server-runtime architecture and prerendering features introduced in v7.0.0. Version 6.3.0 lacks these components entirely - it has no mechanism to process X-React-Router-Prerender-Data or X-React-Router-SPA-Mode headers, no route loaders, no server-side data fetching, and no prerendering capability. The attack chain...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-43865"
      },
      "impact_statement": "not_affected \u2014 Version 6.3.0 is NOT AFFECTED by CVE-2025-43865. The vulnerability requires the server-runtime architecture and prerendering features introduced in v7.0.0. Version 6.3.0 lacks these components entirely - it has no mechanism to process X-React-Router-Prerender-Data or X-React-Router-SPA-Mode headers, no route loaders, no server-side data fetching, and no prerendering capability. The attack chain..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/react-router@6.3.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/react-router@6.3.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59057 does not affect version 6.3.0-tuxcare.2 of react-router. not_affected \u2014 Version 6.3.0 is not affected by CVE-2025-59057. The vulnerability exists in the Meta component's JSON-LD handling, which was introduced in React Router version 7.x. Version 6.3.0 predates this feature and does not contain the vulnerable code path.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-59057"
      },
      "impact_statement": "not_affected \u2014 Version 6.3.0 is not affected by CVE-2025-59057. The vulnerability exists in the Meta component's JSON-LD handling, which was introduced in React Router version 7.x. Version 6.3.0 predates this feature and does not contain the vulnerable code path."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/react-router@6.3.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/react-router@6.3.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68470 is fixed in version 6.3.0-tuxcare.2 of react-router.",
      "vulnerability": {
        "name": "CVE-2025-68470"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/react-router@6.3.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/react-router@6.3.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22029 does not affect version 6.3.0-tuxcare.2 of react-router. not_affected \u2014 React Router 6.3.0 is not affected by CVE-2026-22029. The vulnerability requires loader/action redirect response handling in Framework Mode or Data Mode, which were introduced in React Router 6.4+. Version 6.3.0 uses only declarative routing mode (<BrowserRouter>, <Routes>, <Route>), which the CVE explicitly states is not impacted. The vulnerable code path (normalizeRedirectLocation function pr...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-22029"
      },
      "impact_statement": "not_affected \u2014 React Router 6.3.0 is not affected by CVE-2026-22029. The vulnerability requires loader/action redirect response handling in Framework Mode or Data Mode, which were introduced in React Router 6.4+. Version 6.3.0 uses only declarative routing mode (<BrowserRouter>, <Routes>, <Route>), which the CVE explicitly states is not impacted. The vulnerable code path (normalizeRedirectLocation function pr..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/react-router@6.3.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/react-router@6.3.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22030 does not affect version 6.3.0-tuxcare.2 of react-router. not_affected \u2014 React Router v6.3.0 is not affected by CVE-2026-22030. This version is a client-side routing library with no server-side request handling infrastructure. The CSRF vulnerability concerns server-side action handlers that process HTTP POST requests - functionality introduced in React Router v7 with the react-router-dev package and server-runtime components. Version 6.3.0 does not receive or proces...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-22030"
      },
      "impact_statement": "not_affected \u2014 React Router v6.3.0 is not affected by CVE-2026-22030. This version is a client-side routing library with no server-side request handling infrastructure. The CSRF vulnerability concerns server-side action handlers that process HTTP POST requests - functionality introduced in React Router v7 with the react-router-dev package and server-runtime components. Version 6.3.0 does not receive or proces..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/react-router@6.3.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/react-router@6.3.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42211 does not affect version 6.3.0-tuxcare.2 of react-router. not_affected \u2014 React Router version 6.3.0-tuxcare.1 is not affected by CVE-2026-42211. The vulnerability exists in Framework Mode's turbo-stream error deserialization (versions 7.0.0-7.14.1), which does not exist in version 6.3.0. This version only supports Declarative Mode (BrowserRouter), which the CVE explicitly excludes from the vulnerability scope.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-42211"
      },
      "impact_statement": "not_affected \u2014 React Router version 6.3.0-tuxcare.1 is not affected by CVE-2026-42211. The vulnerability exists in Framework Mode's turbo-stream error deserialization (versions 7.0.0-7.14.1), which does not exist in version 6.3.0. This version only supports Declarative Mode (BrowserRouter), which the CVE explicitly excludes from the vulnerability scope."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/react-router@6.3.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/react-router@6.3.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48038 is a false positive for react-router 6.3.0-tuxcare.2. false_positive \u2014 CVE-2026-48038 is a wrong-project match. The CVE affects joi (a JavaScript validation library), but this repository is react-router (a React routing library). While @hapi/joi@15.1.1 appears as a transitive dev dependency via @react-native-community/cli, react-router's source code never imports or uses joi, and the repository contains no joi validation logic. React-router handles URL routing, no...",
      "vulnerability": {
        "name": "CVE-2026-48038"
      },
      "impact_statement": "false_positive \u2014 CVE-2026-48038 is a wrong-project match. The CVE affects joi (a JavaScript validation library), but this repository is react-router (a React routing library). While @hapi/joi@15.1.1 appears as a transitive dev dependency via @react-native-community/cli, react-router's source code never imports or uses joi, and the repository contains no joi validation logic. React-router handles URL routing, no..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/react-router@6.3.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/react-router@6.3.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53668 affects version 6.3.0-tuxcare.2 of react-router.",
      "vulnerability": {
        "name": "CVE-2026-53668"
      },
      "action_statement": "Vulnerability CVE-2026-53668 affects version 6.3.0-tuxcare.2 of react-router."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/react-router@6.3.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/react-router@6.3.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53669 is fixed in version 6.3.0-tuxcare.2 of react-router.",
      "vulnerability": {
        "name": "CVE-2026-53669"
      }
    }
  ]
}
