{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:41729edd-3a36-5d9e-aa48-b77d4568f612",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/react-router-dom-v5-compat@6.3.0-tuxcare.1",
      "type": "library",
      "name": "react-router-dom-v5-compat",
      "version": "6.3.0-tuxcare.1",
      "purl": "pkg:npm/react-router-dom-v5-compat@6.3.0-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:06da570f-d4d9-567e-8547-4022e9cf4ab6",
      "id": "CVE-2022-25883",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-25883 is fixed in version 6.3.0-tuxcare.1 of react-router-dom-v5-compat."
      },
      "affects": [
        {
          "ref": "pkg:npm/react-router-dom-v5-compat@6.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:970a5070-c48f-5425-803f-7d1c636eb2f7",
      "id": "CVE-2025-43864",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-43864 does not affect version 6.3.0-tuxcare.1 of react-router-dom-v5-compat. not_affected \u2014 React Router v6.3.0-tuxcare.1 is not affected by CVE-2025-43864. The vulnerability is specific to React Router v7.x's server-side request handling and prerendering features, which do not exist in v6.3.0. The target version is a client-side routing library that does not process HTTP request headers."
      },
      "affects": [
        {
          "ref": "pkg:npm/react-router-dom-v5-compat@6.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d904b2f6-32d7-596c-9c7b-6e61bae27e83",
      "id": "CVE-2025-43865",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-43865 does not affect version 6.3.0-tuxcare.1 of react-router-dom-v5-compat. not_affected \u2014 Version 6.3.0 is NOT AFFECTED by CVE-2025-43865. The vulnerability requires the server-runtime architecture and prerendering features introduced in v7.0.0. Version 6.3.0 lacks these components entirely - it has no mechanism to process X-React-Router-Prerender-Data or X-React-Router-SPA-Mode headers, no route loaders, no server-side data fetching, and no prerendering capability. The attack chain..."
      },
      "affects": [
        {
          "ref": "pkg:npm/react-router-dom-v5-compat@6.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfbb9b55-9a19-5842-b8a8-26ba11710e7f",
      "id": "CVE-2025-59057",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-59057 does not affect version 6.3.0-tuxcare.1 of react-router-dom-v5-compat. not_affected \u2014 Version 6.3.0 is not affected by CVE-2025-59057. The vulnerability exists in the Meta component's JSON-LD handling, which was introduced in React Router version 7.x. Version 6.3.0 predates this feature and does not contain the vulnerable code path."
      },
      "affects": [
        {
          "ref": "pkg:npm/react-router-dom-v5-compat@6.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c729954f-e8ed-5be4-b1b6-1d9a702f77c6",
      "id": "CVE-2025-68470",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-68470 is fixed in version 6.3.0-tuxcare.1 of react-router-dom-v5-compat."
      },
      "affects": [
        {
          "ref": "pkg:npm/react-router-dom-v5-compat@6.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59d7c67c-902b-5c2c-bdcf-a93827733a5d",
      "id": "CVE-2026-22029",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22029 does not affect version 6.3.0-tuxcare.1 of react-router-dom-v5-compat. not_affected \u2014 React Router 6.3.0 is not affected by CVE-2026-22029. The vulnerability requires loader/action redirect response handling in Framework Mode or Data Mode, which were introduced in React Router 6.4+. Version 6.3.0 uses only declarative routing mode (<BrowserRouter>, <Routes>, <Route>), which the CVE explicitly states is not impacted. The vulnerable code path (normalizeRedirectLocation function pr..."
      },
      "affects": [
        {
          "ref": "pkg:npm/react-router-dom-v5-compat@6.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56ba2904-c130-5f98-bd17-239213e98feb",
      "id": "CVE-2026-22030",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22030 does not affect version 6.3.0-tuxcare.1 of react-router-dom-v5-compat. not_affected \u2014 React Router v6.3.0 is not affected by CVE-2026-22030. This version is a client-side routing library with no server-side request handling infrastructure. The CSRF vulnerability concerns server-side action handlers that process HTTP POST requests - functionality introduced in React Router v7 with the react-router-dev package and server-runtime components. Version 6.3.0 does not receive or proces..."
      },
      "affects": [
        {
          "ref": "pkg:npm/react-router-dom-v5-compat@6.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b383fa85-0006-5fea-bcbd-0f01a048d815",
      "id": "CVE-2026-42211",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42211 does not affect version 6.3.0-tuxcare.1 of react-router-dom-v5-compat. not_affected \u2014 React Router version 6.3.0-tuxcare.1 is not affected by CVE-2026-42211. The vulnerability exists in Framework Mode's turbo-stream error deserialization (versions 7.0.0-7.14.1), which does not exist in version 6.3.0. This version only supports Declarative Mode (BrowserRouter), which the CVE explicitly excludes from the vulnerability scope."
      },
      "affects": [
        {
          "ref": "pkg:npm/react-router-dom-v5-compat@6.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6f010ab-a5a8-5af0-b8a0-9e463548101b",
      "id": "CVE-2026-48038",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-48038 is a false positive for react-router-dom-v5-compat 6.3.0-tuxcare.1. false_positive \u2014 CVE-2026-48038 is a wrong-project match. The CVE affects joi (a JavaScript validation library), but this repository is react-router (a React routing library). While @hapi/joi@15.1.1 appears as a transitive dev dependency via @react-native-community/cli, react-router's source code never imports or uses joi, and the repository contains no joi validation logic. React-router handles URL routing, no..."
      },
      "affects": [
        {
          "ref": "pkg:npm/react-router-dom-v5-compat@6.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81f15b7f-58d9-5b77-968e-533eb1ac8921",
      "id": "CVE-2026-53669",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53669 affects version 6.3.0-tuxcare.1 of react-router-dom-v5-compat."
      },
      "affects": [
        {
          "ref": "pkg:npm/react-router-dom-v5-compat@6.3.0-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/react-router-dom-v5-compat@6.3.0-tuxcare.1"
    }
  ]
}