CRA Readiness Snapshot
What you would have to assess for ENISA reporting tomorrow
No dependency in this snapshot currently appears in CISA's Known Exploited Vulnerabilities catalog. Today, nothing would trigger the 24-hour early-warning obligation of CRA Art. 14. That can change any day a new KEV entry lands, which is exactly what continuous monitoring is for.
All findings (32)
| Package | Version | Advisory | Severity | EPSS | Fixed in | Summary |
|---|---|---|---|---|---|---|
| twig/twig | 3.23.0 | CVE-2026-24425 | HIGH | 0.8% | 3.26.0 | Twig: Possible sandbox bypass when using a source policy |
| twig/twig | 3.23.0 | CVE-2026-46633 | CRITICAL | 0.7% | 3.26.0 | Twig: PHP code injection via `{% use %}` template name |
| symfony/yaml | 7.4.1 | CVE-2026-45304 | LOW | 0.7% | 5.4.52 | Symfony's YAML Parser Vulnerable to Exponential Memory Allocation via Recursive Collection-Alias Expansion ("Billion Laughs") |
| symfony/yaml | 7.4.1 | CVE-2026-45305 | LOW | 0.7% | 5.4.52 | Symfony's YAML Parser has a ReDoS via Catastrophic Backtracking in Parser::cleanup() Regex |
| twig/twig | 3.23.0 | CVE-2026-46640 | HIGH | 0.6% | 3.26.0 | Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation |
| symfony/yaml | 7.4.1 | CVE-2026-45133 | LOW | 0.6% | 5.4.52 | Symfony hardened the parser when handling untrusted input |
| twig/twig | 3.23.0 | CVE-2026-46634 | MODERATE | 0.6% | 3.26.0 | Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name |
| twig/twig | 3.23.0 | CVE-2026-48805 | LOW | 0.5% | 3.27.0 | Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php` |
| twig/twig | 3.23.0 | CVE-2026-46638 | MODERATE | 0.5% | 3.26.0 | Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411) |
| twig/twig | 3.23.0 | CVE-2026-48806 | MODERATE | 0.4% | 3.27.0 | Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys |
| mtdowling/jmespath.php | 2.8.0 | CVE-2026-54133 | CRITICAL | 0.4% | 2.9.1 | jmespath.php has CompilerRuntime code injection via unescaped function names |
| twig/twig | 3.23.0 | CVE-2026-48808 | MODERATE | 0.4% | 3.27.0 | Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface` |
| twig/twig | 3.23.0 | CVE-2026-47732 | HIGH | 0.4% | 3.26.0 | Twig: Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points |
| twig/twig | 3.23.0 | CVE-2026-48807 | MODERATE | 0.4% | 3.27.0 | Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters |
| twig/twig | 3.23.0 | CVE-2026-49981 | HIGH | 0.4% | 3.27.0 | Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template` |
| twig/twig | 3.23.0 | CVE-2026-46635 | LOW | 0.3% | 3.26.0 | Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects) |
| guzzlehttp/psr7 | 2.8.0 | CVE-2026-59882 | MODERATE | 0.3% | 2.12.3 | guzzlehttp/psr7: Host Confusion via Weak URI Host Validation |
| twig/twig | 3.23.0 | CVE-2026-47730 | LOW | 0.3% | 3.26.0 | Twig: XSS in profiler HtmlDumper via unescaped template and profile names |
| twig/twig | 3.23.0 | CVE-2026-46628 | LOW | 0.3% | 3.26.0 | Twig: The `spaceless` filter implicitly marks its output as safe |
| guzzlehttp/guzzle | 7.10.0 | CVE-2026-67354 | MODERATE | 0.3% | 7.15.1 | Guzzle: URI fragments disclosed in redirect Referer headers |
| guzzlehttp/guzzle | 7.10.0 | CVE-2026-67353 | MODERATE | 0.2% | 7.15.1 | Guzzle: Unbounded response cookies risk denial of service |
| guzzlehttp/guzzle | 7.10.0 | CVE-2026-67339 | MODERATE | 0.2% | 7.14.2 | Guzzle: Proxy-Authorization headers can be sent to origin servers |
| guzzlehttp/guzzle | 7.10.0 | CVE-2026-67355 | MODERATE | 0.2% | 7.15.1 | Guzzle: Host-only cookie scope is not preserved |
| guzzlehttp/psr7 | 2.8.0 | CVE-2026-55766 | MODERATE | 0.2% | 2.12.1 | guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization |
| guzzlehttp/guzzle | 7.10.0 | CVE-2026-69246 | HIGH | 0.2% | 7.15.2 | Guzzle: Noncanonical host can bypass host-based checks |
| guzzlehttp/guzzle | 7.10.0 | CVE-2026-55767 | MODERATE | 0.2% | 7.12.1 | guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts |
| guzzlehttp/psr7 | 2.8.0 | CVE-2026-48998 | MODERATE | 0.2% | 2.10.2 | guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation |
| guzzlehttp/psr7 | 2.8.0 | CVE-2026-49214 | MODERATE | 0.2% | 2.10.2 | guzzlehttp/psr7 has CRLF Injection via URI Host Component |
| guzzlehttp/guzzle | 7.10.0 | CVE-2026-59883 | MODERATE | 0.2% | 7.12.3 | Guzzle: Cookie Disclosure and Injection via IP-Address Domains |
| guzzlehttp/guzzle | 7.10.0 | CVE-2026-55568 | MODERATE | 0.1% | 7.12.1 | guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext |
+ 2 further findings (mostly lower severity) — available in the full export.
SBOM summary
17 direct dependencies scanned (17 pinned to exact versions) from composer.lock. Vulnerability data: OSV.dev · exploitation status: CISA KEV · exploit probability: FIRST EPSS. Findings on unpinned dependencies cover the full constraint range and may not apply to the exact version deployed.
Using ENISA's CRA Maturity Assessment Model for SMEs? This snapshot provides evidence for the Vulnerability Management domain and the product-level technical documentation question (1.3) under Governance & Documentation.
This snapshot is an automated readiness assessment, not legal advice and not a conformity assessment under the CRA.