Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.
A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.
Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.
| Product | Status | Versions | Remediation | Source | |
|---|---|---|---|---|---|
| @tanstack/arktype-adapter | affected | >= 1.166.12, < 1.166.16 | vendor fix → 1.166.16 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/arktype-adapter | affected | >= 1.166.15, < 1.166.16 | vendor fix → 1.166.16 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/eslint-plugin-router | affected | >= 1.161.9, < 1.161.13 | vendor fix → 1.161.13 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/eslint-plugin-router | affected | >= 1.161.12, < 1.161.13 | vendor fix → 1.161.13 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/eslint-plugin-start | affected | >= 0.0.4, < 0.0.8 | vendor fix → 0.0.8 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/eslint-plugin-start | affected | >= 0.0.7, < 0.0.8 | vendor fix → 0.0.8 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/history | affected | >= 1.161.9, < 1.161.13 | vendor fix → 1.161.13 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/history | affected | >= 1.161.12, < 1.161.13 | vendor fix → 1.161.13 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/nitro-v2-vite-plugin | affected | >= 1.154.12, < 1.154.16 | vendor fix → 1.154.16 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/nitro-v2-vite-plugin | affected | >= 1.154.15, < 1.154.16 | vendor fix → 1.154.16 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/react-router | affected | >= 1.169.5, < 1.169.9 | vendor fix → 1.169.9 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/react-router | affected | >= 1.169.8, < 1.169.9 | vendor fix → 1.169.9 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/react-router-devtools | affected | >= 1.166.16, < 1.166.20 | vendor fix → 1.166.20 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/react-router-devtools | affected | >= 1.166.19, < 1.166.20 | vendor fix → 1.166.20 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/react-router-ssr-query | affected | >= 1.166.15, < 1.166.19 | vendor fix → 1.166.19 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/react-router-ssr-query | affected | >= 1.166.18, < 1.166.19 | vendor fix → 1.166.19 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/react-start | affected | >= 1.167.68, < 1.167.72 | vendor fix → 1.167.72 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/react-start | affected | >= 1.167.71, < 1.167.72 | vendor fix → 1.167.72 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/react-start-client | affected | >= 1.166.51, < 1.166.55 | vendor fix → 1.166.55 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/react-start-client | affected | >= 1.166.54, < 1.166.55 | vendor fix → 1.166.55 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/react-start-rsc | affected | >= 0.0.47, < 0.0.51 | vendor fix → 0.0.51 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/react-start-rsc | affected | >= 0.0.50, < 0.0.51 | vendor fix → 0.0.51 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/react-start-server | affected | >= 1.166.55, < 1.166.59 | vendor fix → 1.166.59 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/react-start-server | affected | >= 1.166.58, < 1.166.59 | vendor fix → 1.166.59 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/router-cli | affected | >= 1.166.46, < 1.166.50 | vendor fix → 1.166.50 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/router-cli | affected | >= 1.166.49, < 1.166.50 | vendor fix → 1.166.50 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/router-core | affected | >= 1.169.5, < 1.169.9 | vendor fix → 1.169.9 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/router-core | affected | >= 1.169.8, < 1.169.9 | vendor fix → 1.169.9 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/router-devtools | affected | >= 1.166.16, < 1.166.20 | vendor fix → 1.166.20 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/router-devtools | affected | >= 1.166.19, < 1.166.20 | vendor fix → 1.166.20 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/router-devtools-core | affected | >= 1.167.6, < 1.167.10 | vendor fix → 1.167.10 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/router-devtools-core | affected | >= 1.167.9, < 1.167.10 | vendor fix → 1.167.10 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/router-generator | affected | >= 1.166.45, < 1.166.49 | vendor fix → 1.166.49 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/router-generator | affected | >= 1.166.48, < 1.166.49 | vendor fix → 1.166.49 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/router-plugin | affected | >= 1.167.38, < 1.167.42 | vendor fix → 1.167.42 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/router-plugin | affected | >= 1.167.41, < 1.167.42 | vendor fix → 1.167.42 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/router-ssr-query-core | affected | >= 1.168.3, < 1.168.7 | vendor fix → 1.168.7 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/router-ssr-query-core | affected | >= 1.168.6, < 1.168.7 | vendor fix → 1.168.7 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/router-utils | affected | >= 1.161.11, < 1.161.15 | vendor fix → 1.161.15 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/router-utils | affected | >= 1.161.14, < 1.161.15 | vendor fix → 1.161.15 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/router-vite-plugin | affected | >= 1.166.53, < 1.166.57 | vendor fix → 1.166.57 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/router-vite-plugin | affected | >= 1.166.56, < 1.166.57 | vendor fix → 1.166.57 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/solid-router | affected | >= 1.169.5, < 1.169.9 | vendor fix → 1.169.9 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/solid-router | affected | >= 1.169.8, < 1.169.9 | vendor fix → 1.169.9 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/solid-router-devtools | affected | >= 1.166.16, < 1.166.20 | vendor fix → 1.166.20 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/solid-router-devtools | affected | >= 1.166.19, < 1.166.20 | vendor fix → 1.166.20 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/solid-router-ssr-query | affected | >= 1.166.15, < 1.166.19 | vendor fix → 1.166.19 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/solid-router-ssr-query | affected | >= 1.166.18, < 1.166.19 | vendor fix → 1.166.19 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/solid-start | affected | >= 1.167.65, < 1.167.69 | vendor fix → 1.167.69 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/solid-start | affected | >= 1.167.68, < 1.167.69 | vendor fix → 1.167.69 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/solid-start-client | affected | >= 1.166.50, < 1.166.54 | vendor fix → 1.166.54 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/solid-start-client | affected | >= 1.166.53, < 1.166.54 | vendor fix → 1.166.54 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/solid-start-server | affected | >= 1.166.54, < 1.166.58 | vendor fix → 1.166.58 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/solid-start-server | affected | >= 1.166.57, < 1.166.58 | vendor fix → 1.166.58 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/start-client-core | affected | >= 1.168.5, < 1.168.9 | vendor fix → 1.168.9 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/start-client-core | affected | >= 1.168.8, < 1.168.9 | vendor fix → 1.168.9 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/start-fn-stubs | affected | >= 1.161.9, < 1.161.13 | vendor fix → 1.161.13 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/start-fn-stubs | affected | >= 1.161.12, < 1.161.13 | vendor fix → 1.161.13 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/start-plugin-core | affected | >= 1.169.23, < 1.169.27 | vendor fix → 1.169.27 | osv GHSA-g7cv-rxg3-hmpx | |
| @tanstack/start-plugin-core | affected | >= 1.169.26, < 1.169.27 | vendor fix → 1.169.27 | osv GHSA-g7cv-rxg3-hmpx |
A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.