CRA Readiness Snapshot
What you would have to assess for ENISA reporting tomorrow
No dependency in this snapshot currently appears in CISA's Known Exploited Vulnerabilities catalog. Today, nothing would trigger the 24-hour early-warning obligation of CRA Art. 14. That can change any day a new KEV entry lands, which is exactly what continuous monitoring is for.
⚠ No lockfile — SBOM is not reproducible
This scan is based on a manifest (composer.json), not a lockfile. 7 of 7 dependencies are version ranges, so the exact shipped versions — and their transitive dependencies — cannot be verified. Under the CRA's full obligations (11 December 2027) you must produce a machine-readable SBOM of what you actually ship. Committing a lockfile is the single highest-impact fix in this report.
All findings (21)
| Package | Version | Advisory | Severity | EPSS | Fixed in | Summary |
|---|---|---|---|---|---|---|
| symfony/http-foundation dev | ^7.4|^8.0 | CVE-2018-14773 | MODERATE | 58.1% | 2.7.49 | Symfony HTTP Foundation web cache poisoning |
| symfony/dependency-injection dev | ^7.4|^8.0 | CVE-2019-10910 | CRITICAL | 5.9% | 2.7.51 | Symfony Service IDs Allow Injection |
| symfony/http-foundation dev | ^7.4|^8.0 | CVE-2013-4752 | MODERATE | 2.3% | 2.0.24 | Symfony Host Header Injection vulnerability in the HttpFoundation component |
| symfony/http-foundation dev | ^7.4|^8.0 | CVE-2019-18888 | HIGH | 2.2% | 2.8.52 | Argument injection in a MimeTypeGuesser in Symfony |
| symfony/http-foundation dev | ^7.4|^8.0 | CVE-2012-6431 | MODERATE | 1.9% | 2.0.19 | Symfony Allows URI Restrictions Bypass Via Double-Encoded String |
| symfony/http-foundation dev | ^7.4|^8.0 | CVE-2019-10913 | CRITICAL | 1.9% | 2.7.51 | Invalid HTTP method overrides allow possible XSS or other attacks in Symfony |
| symfony/yaml dev | ^7.4|^8.0 | CVE-2013-1348 | HIGH | 1.6% | 2.0.22 | Symphony Vulnerable to PHP Code Injection via YAML Parsing |
| symfony/yaml dev | ^7.4|^8.0 | CVE-2013-1397 | HIGH | 1.6% | 2.0.22 | Symfony Arbitrary PHP code Execution |
| symfony/http-foundation dev | ^7.4|^8.0 | CVE-2018-11386 | MODERATE | 1.6% | 2.7.48 | Symfony DoS |
| symfony/http-foundation dev | ^7.4|^8.0 | CVE-2025-64500 | HIGH | 1.3% | 5.4.50 | Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass |
| symfony/http-foundation dev | ^7.4|^8.0 | CVE-2020-5255 | LOW | 1.3% | 4.4.7 | Prevent cache poisoning via a Response Content-Type header in Symfony |
| symfony/yaml dev | ^7.4|^8.0 | CVE-2026-45304 | LOW | 0.7% | 5.4.52 | Symfony's YAML Parser Vulnerable to Exponential Memory Allocation via Recursive Collection-Alias Expansion ("Billion Laughs") |
| symfony/yaml dev | ^7.4|^8.0 | CVE-2026-45305 | LOW | 0.7% | 5.4.52 | Symfony's YAML Parser has a ReDoS via Catastrophic Backtracking in Parser::cleanup() Regex |
| symfony/yaml dev | ^7.4|^8.0 | CVE-2026-45133 | LOW | 0.6% | 5.4.52 | Symfony hardened the parser when handling untrusted input |
| symfony/http-foundation dev | ^7.4|^8.0 | CVE-2026-48736 | MODERATE | 0.6% | 6.4.41 | Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpCli... |
| symfony/http-foundation dev | ^7.4|^8.0 | CVE-2024-50345 | LOW | 0.6% | 5.4.46 | Symfony vulnerable to open redirect via browser-sanitized URLs |
| symfony/dependency-injection dev | ^7.4|^8.0 | GHSA-c636-cg5r-2498 | HIGH | — | 2.0.17 | Symfony XML Entity Expansion security vulnerability |
| symfony/http-foundation dev | ^7.4|^8.0 | CVE-2014-5244 | HIGH | — | 2.3.19 | Symfony vulnerable to denial of service via a malicious HTTP Host header |
| symfony/http-foundation dev | ^7.4|^8.0 | CVE-2014-6061 | MODERATE | — | 2.3.19 | Symfony has a security issue when parsing the Authorization header |
| symfony/http-foundation dev | ^7.4|^8.0 | CVE-2015-2309 | MODERATE | — | 2.3.27 | Symfony has unsafe methods in the Request class |
| symfony/http-foundation dev | ^7.4|^8.0 | GHSA-vfm6-r2gc-pwww | MODERATE | — | 2.0.19 | Symfony2 security issue when the trust proxy mode is enabled |
SBOM summary
7 direct dependencies scanned (0 pinned to exact versions) from composer.json. Vulnerability data: OSV.dev · exploitation status: CISA KEV · exploit probability: FIRST EPSS. Findings on unpinned dependencies cover the full constraint range and may not apply to the exact version deployed.
Using ENISA's CRA Maturity Assessment Model for SMEs? This snapshot provides evidence for the Vulnerability Management domain and the product-level technical documentation question (1.3) under Governance & Documentation.
This snapshot is an automated readiness assessment, not legal advice and not a conformity assessment under the CRA.