CRAIR CRA Readiness Snapshot

doctrine/migrations · composer.json · 10 Sep 2026, 10:12 UTC
0 days until the EU Cyber Resilience Act 24-hour reporting obligation applies (11 September 2026), including for products already on the market.
22
dependencies in scope
20
known vulnerabilities
1
actively exploited (CISA KEV)
100.0%
highest exploit probability (EPSS)

What you would have to assess for ENISA reporting tomorrow

From 11 September 2026, an actively exploited vulnerability in software you ship must be reported to ENISA within 24 hours of awareness (CRA Art. 14). In this snapshot, 1 finding is in the CISA KEV catalog (0 in production dependencies):

PackageYour versionCVEFixed inExploit context
phpunit/phpunit dev ^10.3 || ^11.0 || ^12.0 (unpinned) CVE-2017-9841 4.8.28 KEV listed 2022-02-15

⚠ No lockfile — SBOM is not reproducible

This scan is based on a manifest (composer.json), not a lockfile. 22 of 22 dependencies are version ranges, so the exact shipped versions — and their transitive dependencies — cannot be verified. Under the CRA's full obligations (11 December 2027) you must produce a machine-readable SBOM of what you actually ship. Committing a lockfile is the single highest-impact fix in this report.

All findings (20)

PackageVersionAdvisorySeverityEPSSFixed inSummary
symfony/cache dev ^5.4 || ^6.0 || ^7.0 || ^8.0 CVE-2019-18889 CRITICAL 33.2% 3.4.35 Symfony Unsafe Cache Serialization Could Enable RCE
symfony/var-exporter ^6.2 || ^7.0 || ^8.0 CVE-2019-11325 CRITICAL 3.4% 4.2.12 Improper Input Validation in Symfony
doctrine/dbal ^3.6 || ^4 CVE-2021-43608 CRITICAL 2.4% 3.1.4 DBAL 3 SQL Injection Security Vulnerability
symfony/cache dev ^5.4 || ^6.0 || ^7.0 || ^8.0 CVE-2019-10912 HIGH 2.3% 3.4.26 Deserialization of untrusted data in Symfony
symfony/yaml dev ^5.4 || ^6.0 || ^7.0 || ^8.0 CVE-2013-1348 HIGH 1.6% 2.0.22 Symphony Vulnerable to PHP Code Injection via YAML Parsing
symfony/yaml dev ^5.4 || ^6.0 || ^7.0 || ^8.0 CVE-2013-1397 HIGH 1.6% 2.0.22 Symfony Arbitrary PHP code Execution
symfony/yaml dev ^5.4 || ^6.0 || ^7.0 || ^8.0 CVE-2026-45304 LOW 0.7% 5.4.52 Symfony's YAML Parser Vulnerable to Exponential Memory Allocation via Recursive Collection-Alias Expansion ("Billion Laughs")
symfony/yaml dev ^5.4 || ^6.0 || ^7.0 || ^8.0 CVE-2026-45305 LOW 0.7% 5.4.52 Symfony's YAML Parser has a ReDoS via Catastrophic Backtracking in Parser::cleanup() Regex
symfony/yaml dev ^5.4 || ^6.0 || ^7.0 || ^8.0 CVE-2026-45133 LOW 0.6% 5.4.52 Symfony hardened the parser when handling untrusted input
symfony/cache dev ^5.4 || ^6.0 || ^7.0 || ^8.0 CVE-2026-45073 MODERATE 0.5% 5.4.52 Symfony Vulnerable to SQL Injection in PdoAdapter::doClear() via Unsanitized $prefix
symfony/process dev ^5.4 || ^6.0 || ^7.0 || ^8.0 CVE-2024-51736 HIGH 0.4% 5.4.46 Symfony vulnerable to command execution hijack on Windows with Process class
doctrine/orm dev ^2.13 || ^3 CVE-2015-5723 HIGH 0.4% 2.5.1 Doctrine Security Misconfiguration Vulnerability
phpunit/phpunit dev ^10.3 || ^11.0 || ^12.0 CVE-2026-24765 HIGH 0.3% 8.5.52 PHPUnit Vulnerable to Unsafe Deserialization in PHPT Code Coverage Handling
symfony/process dev ^5.4 || ^6.0 || ^7.0 || ^8.0 CVE-2026-24739 MODERATE 0.2% 5.4.51 Symfony's incorrect argument escaping under MSYS2/Git Bash can lead to destructive file operations on Windows
phpunit/phpunit dev ^10.3 || ^11.0 || ^12.0 CVE-2026-41570 HIGH 0.2% 12.5.22 PHPUnit has Argument injection via newline in PHP INI values that are forwarded to child processes
doctrine/orm dev ^2.13 || ^3 GHSA-6q9v-4hq6-5m67 CRITICAL 2.0.3 Doctrine SQL injection vulnerability
doctrine/dbal ^3.6 || ^4 GHSA-76w8-mqx4-wjrf HIGH 2.0.8 Doctrine DBAL SQL injection possibility
doctrine/orm dev ^2.13 || ^3 GHSA-vjrg-wpm8-rhrw HIGH 2.8.4 doctrine/orm Regression in Query Parenthesis can have Security Implications
phpunit/phpunit dev ^10.3 || ^11.0 || ^12.0 GHSA-mh6w-vxff-9wqp HIGH 12.5.22 PHPUnit: Argument injection via newline in PHP INI values forwarded to child processes
phpunit/phpunit dev ^10.3 || ^11.0 || ^12.0 CVE-2017-9841 KEV CRITICAL 100.0% 4.8.28 Code Injection in PHPUnit

SBOM summary

22 direct dependencies scanned (0 pinned to exact versions) from composer.json. Vulnerability data: OSV.dev · exploitation status: CISA KEV · exploit probability: FIRST EPSS. Findings on unpinned dependencies cover the full constraint range and may not apply to the exact version deployed.

Using ENISA's CRA Maturity Assessment Model for SMEs? This snapshot provides evidence for the Vulnerability Management domain and the product-level technical documentation question (1.3) under Governance & Documentation.

This snapshot is an automated readiness assessment, not legal advice and not a conformity assessment under the CRA.

Download SBOM (CycloneDX) Want this to watch your product continuously and draft the ENISA report the day something turns exploited? Start monitoring for €99/mo Talk to us