CRAIR CRA Readiness Snapshot

opencart/opencart · composer.lock · 16 Sep 2026, 11:10 UTC
0 days until the EU Cyber Resilience Act 24-hour reporting obligation applies (11 September 2026), including for products already on the market.
17
dependencies in scope
32
known vulnerabilities
0
actively exploited (CISA KEV)
0.8%
highest exploit probability (EPSS)

What you would have to assess for ENISA reporting tomorrow

No dependency in this snapshot currently appears in CISA's Known Exploited Vulnerabilities catalog. Today, nothing would trigger the 24-hour early-warning obligation of CRA Art. 14. That can change any day a new KEV entry lands, which is exactly what continuous monitoring is for.

All findings (32)

PackageVersionAdvisorySeverityEPSSFixed inSummary
twig/twig 3.23.0 CVE-2026-24425 HIGH 0.8% 3.26.0 Twig: Possible sandbox bypass when using a source policy
twig/twig 3.23.0 CVE-2026-46633 CRITICAL 0.7% 3.26.0 Twig: PHP code injection via `{% use %}` template name
symfony/yaml 7.4.1 CVE-2026-45304 LOW 0.7% 5.4.52 Symfony's YAML Parser Vulnerable to Exponential Memory Allocation via Recursive Collection-Alias Expansion ("Billion Laughs")
symfony/yaml 7.4.1 CVE-2026-45305 LOW 0.7% 5.4.52 Symfony's YAML Parser has a ReDoS via Catastrophic Backtracking in Parser::cleanup() Regex
twig/twig 3.23.0 CVE-2026-46640 HIGH 0.6% 3.26.0 Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation
symfony/yaml 7.4.1 CVE-2026-45133 LOW 0.6% 5.4.52 Symfony hardened the parser when handling untrusted input
twig/twig 3.23.0 CVE-2026-46634 MODERATE 0.6% 3.26.0 Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name
twig/twig 3.23.0 CVE-2026-48805 LOW 0.5% 3.27.0 Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`
twig/twig 3.23.0 CVE-2026-46638 MODERATE 0.5% 3.26.0 Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)
twig/twig 3.23.0 CVE-2026-48806 MODERATE 0.4% 3.27.0 Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys
mtdowling/jmespath.php 2.8.0 CVE-2026-54133 CRITICAL 0.4% 2.9.1 jmespath.php has CompilerRuntime code injection via unescaped function names
twig/twig 3.23.0 CVE-2026-48808 MODERATE 0.4% 3.27.0 Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`
twig/twig 3.23.0 CVE-2026-47732 HIGH 0.4% 3.26.0 Twig: Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points
twig/twig 3.23.0 CVE-2026-48807 MODERATE 0.4% 3.27.0 Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters
twig/twig 3.23.0 CVE-2026-49981 HIGH 0.4% 3.27.0 Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`
twig/twig 3.23.0 CVE-2026-46635 LOW 0.3% 3.26.0 Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)
guzzlehttp/psr7 2.8.0 CVE-2026-59882 MODERATE 0.3% 2.12.3 guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
twig/twig 3.23.0 CVE-2026-47730 LOW 0.3% 3.26.0 Twig: XSS in profiler HtmlDumper via unescaped template and profile names
twig/twig 3.23.0 CVE-2026-46628 LOW 0.3% 3.26.0 Twig: The `spaceless` filter implicitly marks its output as safe
guzzlehttp/guzzle 7.10.0 CVE-2026-67354 MODERATE 0.3% 7.15.1 Guzzle: URI fragments disclosed in redirect Referer headers
guzzlehttp/guzzle 7.10.0 CVE-2026-67353 MODERATE 0.2% 7.15.1 Guzzle: Unbounded response cookies risk denial of service
guzzlehttp/guzzle 7.10.0 CVE-2026-67339 MODERATE 0.2% 7.14.2 Guzzle: Proxy-Authorization headers can be sent to origin servers
guzzlehttp/guzzle 7.10.0 CVE-2026-67355 MODERATE 0.2% 7.15.1 Guzzle: Host-only cookie scope is not preserved
guzzlehttp/psr7 2.8.0 CVE-2026-55766 MODERATE 0.2% 2.12.1 guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
guzzlehttp/guzzle 7.10.0 CVE-2026-69246 HIGH 0.2% 7.15.2 Guzzle: Noncanonical host can bypass host-based checks
guzzlehttp/guzzle 7.10.0 CVE-2026-55767 MODERATE 0.2% 7.12.1 guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts
guzzlehttp/psr7 2.8.0 CVE-2026-48998 MODERATE 0.2% 2.10.2 guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
guzzlehttp/psr7 2.8.0 CVE-2026-49214 MODERATE 0.2% 2.10.2 guzzlehttp/psr7 has CRLF Injection via URI Host Component
guzzlehttp/guzzle 7.10.0 CVE-2026-59883 MODERATE 0.2% 7.12.3 Guzzle: Cookie Disclosure and Injection via IP-Address Domains
guzzlehttp/guzzle 7.10.0 CVE-2026-55568 MODERATE 0.1% 7.12.1 guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext

+ 2 further findings (mostly lower severity) — available in the full export.

SBOM summary

17 direct dependencies scanned (17 pinned to exact versions) from composer.lock. Vulnerability data: OSV.dev · exploitation status: CISA KEV · exploit probability: FIRST EPSS. Findings on unpinned dependencies cover the full constraint range and may not apply to the exact version deployed.

Using ENISA's CRA Maturity Assessment Model for SMEs? This snapshot provides evidence for the Vulnerability Management domain and the product-level technical documentation question (1.3) under Governance & Documentation.

This snapshot is an automated readiness assessment, not legal advice and not a conformity assessment under the CRA.

Download SBOM (CycloneDX) Want this to watch your product continuously and draft the ENISA report the day something turns exploited? Start monitoring for €99/mo Talk to us