{"api_version":"v1","generated_at":"2026-10-07T08:10:00+00:00","product":{"cve_count":21,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-remix-run-react-router-421df4c85ab5","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/react-router","name":"react-router","next_cursor":null,"observations":[{"affected":">= 6.0.0, < 7.18.0","affected_versions_present":true,"cve_id":"CVE-2026-53669","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-53669","fixed":"7.18.0.","last_modified":"2026-07-28T16:04:33.480Z","patch_url":"https://github.com/remix-run/react-router/pull/15176","primary_source":"","published":"2026-07-27T22:11:39.056Z"},{"affected":">= 7.0.0, < 7.18.0","affected_versions_present":true,"cve_id":"CVE-2026-55685","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55685","fixed":"7.18.0.","last_modified":"2026-07-28T13:40:04.996Z","patch_url":"https://github.com/remix-run/react-router/pull/15186","primary_source":"","published":"2026-07-27T21:45:57.751Z"},{"affected":">= 6.30.2, <= 6.30.4; >= 7.9.6, < 7.13.0","affected_versions_present":true,"cve_id":"CVE-2026-53668","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-53668","fixed":"7.13.0.","last_modified":"2026-07-28T13:44:11.335Z","patch_url":"https://github.com/remix-run/react-router/pull/14718","primary_source":"","published":"2026-07-27T21:42:17.641Z"},{"affected":">= 7.11.0, < 7.18.0","affected_versions_present":true,"cve_id":"CVE-2026-53667","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-53667","fixed":"7.18.0.","last_modified":"2026-07-28T13:51:15.333Z","patch_url":"https://github.com/remix-run/react-router/pull/15177","primary_source":"","published":"2026-07-27T21:21:16.084Z"},{"affected":">= 6.4.0, < 7.18.0","affected_versions_present":true,"cve_id":"CVE-2026-53666","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-53666","fixed":"7.18.0.","last_modified":"2026-07-28T15:19:58.603Z","patch_url":"https://github.com/remix-run/react-router/pull/15175","primary_source":"","published":"2026-07-27T21:14:49.547Z"},{"affected":">= 7.12.0, < 7.15.1; >= 2.17.3, < 2.17.5","affected_versions_present":true,"cve_id":"CVE-2026-53663","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-53663","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-22T19:52:50.287Z","patch_url":"","primary_source":"","published":"2026-06-22T17:39:29.160Z"},{"affected":">= 7.0.0, < 7.15.0; >= 2.10.0, < 2.17.5","affected_versions_present":true,"cve_id":"CVE-2026-42342","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42342","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2026-06-03T13:52:43.400Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-42342","primary_source":"","published":"2026-06-02T18:23:02.765Z"},{"affected":">= 7.0.0, < 7.14.2","affected_versions_present":true,"cve_id":"CVE-2026-42211","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42211","fixed":"Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.","last_modified":"2026-06-03T14:08:30.154Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-42211","primary_source":"","published":"2026-06-02T18:18:46.706Z"},{"affected":">= 7.0.0, < 7.14.1; >= 6.7.0, < 6.30.4; >= 1.3.0, < 1.23.3","affected_versions_present":true,"cve_id":"CVE-2026-40181","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40181","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/4.18/html/updating_openshift_data_foundation/updating-ocs-to-odf_rhodf","last_modified":"2026-08-04T21:26:41.037Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-40181","primary_source":"","published":"2026-06-02T17:55:09.919Z"},{"affected":">= 7.0.0, < 7.14.0; < 3.0.0","affected_versions_present":true,"cve_id":"CVE-2026-34077","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34077","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-03T13:19:02.279Z","patch_url":"","primary_source":"","published":"2026-06-02T17:31:35.579Z"},{"affected":">= 7.7.0, < 7.13.2","affected_versions_present":true,"cve_id":"CVE-2026-33245","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33245","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2026-06-03T19:09:34.483Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-33245","primary_source":"","published":"2026-06-02T17:14:50.377Z"},{"affected":">= 7.5.1, < 7.13.2","affected_versions_present":true,"cve_id":"CVE-2026-33244","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33244","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-02T17:28:13.207Z","patch_url":"https://www.suse.com/security/cve/CVE-2026-33244","primary_source":"","published":"2026-06-02T16:59:31.104Z"},{"affected":"@remix-run/router < 2.17.3; react-router >= 7.0.0, < 7.12.0","affected_versions_present":true,"cve_id":"CVE-2026-22030","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-22030","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-01-12T18:09:39.441Z","patch_url":"","primary_source":"","published":"2026-01-10T02:42:44.603Z"},{"affected":"react-router: >= 7.0.0, < 7.12.0; @remix-run/router: < 1.23.2","affected_versions_present":true,"cve_id":"CVE-2026-22029","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-22029","fixed":"RHSA-2026:3959: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9","last_modified":"2026-09-10T12:04:57.289Z","patch_url":"https://github.com/remix-run/react-router/security/advisories/GHSA-2w69-qvjg-hvjx","primary_source":"","published":"2026-01-10T02:42:32.736Z"},{"affected":"@remix-run/react < 2.17.3; react-router >= 7.0.0, < 7.12.0","affected_versions_present":true,"cve_id":"CVE-2026-21884","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-21884","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-15T01:19:46.847Z","patch_url":"","primary_source":"","published":"2026-01-10T02:41:44.944Z"},{"affected":"@react-router/node >= 7.0.0, < 7.9.4; @remix-run/deno < 2.17.2; @remix-run/node < 2.17.2","affected_versions_present":true,"cve_id":"CVE-2025-61686","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-61686","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-15T01:25:34.058Z","patch_url":"","primary_source":"","published":"2026-01-10T02:41:22.741Z"},{"affected":"@remix-run/react >= 1.15.0, < 2.17.1; react-router >= 7.0.0, < 7.9.0","affected_versions_present":true,"cve_id":"CVE-2025-59057","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-59057","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-15T01:25:51.670Z","patch_url":"","primary_source":"","published":"2026-01-10T02:40:25.142Z"},{"affected":">= 7.0.0, < 7.9.6; >= 6.0.0, < 6.30.2","affected_versions_present":true,"cve_id":"CVE-2025-68470","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-68470","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/4.18/html/updating_openshift_data_foundation/updating-ocs-to-odf_rhodf","last_modified":"2026-01-12T18:17:43.794Z","patch_url":"https://access.redhat.com/security/cve/CVE-2025-68470","primary_source":"","published":"2026-01-10T02:39:41.078Z"},{"affected":">= 7.0, < 7.5.2","affected_versions_present":true,"cve_id":"CVE-2025-43865","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-43865","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-25T15:16:00.202Z","patch_url":"","primary_source":"","published":"2025-04-25T00:18:53.222Z"},{"affected":">= 7.2.0, < 7.5.2","affected_versions_present":true,"cve_id":"CVE-2025-43864","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-43864","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-25T15:18:38.495Z","patch_url":"","primary_source":"","published":"2025-04-25T00:18:16.058Z"},{"affected":">= 7.0.0, < 7.4.1; >= 2.11.1, < 2.16.3","affected_versions_present":true,"cve_id":"CVE-2025-31137","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-31137","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-02T15:11:11.594Z","patch_url":"","primary_source":"","published":"2025-04-01T18:20:32.660Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"remix-run"}}
