{"api_version":"v1","generated_at":"2026-10-02T08:00:00+00:00","product":{"cve_count":1,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-tanstack-tanstack-7aee146d0c31","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/tanstack","name":"TanStack","next_cursor":null,"observations":[{"affected":"arktype-adapter: 1.166.12, 1.166.15; eslint-plugin-router: 1.161.9, 1.161.12; eslint-plugin-start: 0.0.4, 0.0.7; history: 1.161.9, 1.161.12; nitro-v2-vite-plugin: 1.154.12, 1.154.15; react-router: 1.169.5, 1.169.8; react-router-devtools: 1.166.16, 1.166.19; react-router-ssr-query: 1.166.15, 1.166.18; react-start: 1.167.68, 1.167.71; react-start-client: 1.166.51, 1.166.54; react-start-rsc: 0.0.47, 0.0.50; react-start-server: 1.166.55, 1.166.58; router-cli: 1.166.46, 1.166.49; router-core: 1.169.5, 1.169.8; router-devtools: 1.166.16, 1.166.19; router-devtools-core: 1.167.6, 1.167.9; router-generator: 1.166.45, 1.166.48; router-plugin: 1.167.38, 1.167.41; router-ssr-query-core: 1.168.3, 1.168.6; router-utils: 1.161.11, 1.161.14; outer-vite-plugin: 1.166.53, 1.166.56; solid-router: 1.169.5, 1.169.8; solid-router-devtools: 1.166.16, 1.166.19; solid-router-ssr-query: 1.166.15, 1.166.18; solid-start: 1.167.65, 1.167.68; solid-start-client: 1.166.50, 1.166.53; solid-start-server: 1.166.54, 1.166.57; start-client-core: 1.168.5, 1.168.8; start-fn-stubs: 1.161.9, 1.161.12; start-plugin-core: 1.169.23, 1.169.26; start-server-core: 1.167.33, 1.167.36; start-static-server-functions: 1.166.44, 1.166.47; start-storage-context: 1.166.38, 1.166.41; valibot-adapter: 1.166.12, 1.166.15; virtual-file-routes: 1.161.10, 1.161.13; vue-router: 1.169.5, 1.169.8; vue-router-devtools: 1.166.16, 1.166.19; vue-router-ssr-query: 1.166.15, 1.166.18; vue-start: 1.167.61, 1.167.64; vue-start-client: 1.166.46, 1.166.49; vue-start-server: 1.166.50, 1.166.53; zod-adapter: 1.166.12, 1.166.15","affected_versions_present":true,"cve_id":"CVE-2026-45321","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45321","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-04T03:56:09.005Z","patch_url":"https://github.com/TanStack/router/security/advisories/GHSA-g7cv-rxg3-hmpx","primary_source":"","published":"2026-05-12T00:12:35.452Z"}],"source_generated_at":"2026-10-02T06:19:59.452Z","vendor":"TanStack"}}
