CRA Readiness Snapshot
What you would have to assess for ENISA reporting tomorrow
From 11 September 2026, an actively exploited vulnerability in software you ship must be reported to ENISA within 24 hours of awareness (CRA Art. 14). In this snapshot, 1 finding is in the CISA KEV catalog (0 in production dependencies):
| Package | Your version | CVE | Fixed in | Exploit context |
|---|---|---|---|---|
| phpunit/phpunit dev | ^10.3 || ^11.0 || ^12.0 (unpinned) | CVE-2017-9841 | 4.8.28 | KEV listed 2022-02-15 |
⚠ No lockfile — SBOM is not reproducible
This scan is based on a manifest (composer.json), not a lockfile. 22 of 22 dependencies are version ranges, so the exact shipped versions — and their transitive dependencies — cannot be verified. Under the CRA's full obligations (11 December 2027) you must produce a machine-readable SBOM of what you actually ship. Committing a lockfile is the single highest-impact fix in this report.
All findings (20)
| Package | Version | Advisory | Severity | EPSS | Fixed in | Summary |
|---|---|---|---|---|---|---|
| symfony/cache dev | ^5.4 || ^6.0 || ^7.0 || ^8.0 | CVE-2019-18889 | CRITICAL | 33.2% | 3.4.35 | Symfony Unsafe Cache Serialization Could Enable RCE |
| symfony/var-exporter | ^6.2 || ^7.0 || ^8.0 | CVE-2019-11325 | CRITICAL | 3.4% | 4.2.12 | Improper Input Validation in Symfony |
| doctrine/dbal | ^3.6 || ^4 | CVE-2021-43608 | CRITICAL | 2.4% | 3.1.4 | DBAL 3 SQL Injection Security Vulnerability |
| symfony/cache dev | ^5.4 || ^6.0 || ^7.0 || ^8.0 | CVE-2019-10912 | HIGH | 2.3% | 3.4.26 | Deserialization of untrusted data in Symfony |
| symfony/yaml dev | ^5.4 || ^6.0 || ^7.0 || ^8.0 | CVE-2013-1348 | HIGH | 1.6% | 2.0.22 | Symphony Vulnerable to PHP Code Injection via YAML Parsing |
| symfony/yaml dev | ^5.4 || ^6.0 || ^7.0 || ^8.0 | CVE-2013-1397 | HIGH | 1.6% | 2.0.22 | Symfony Arbitrary PHP code Execution |
| symfony/yaml dev | ^5.4 || ^6.0 || ^7.0 || ^8.0 | CVE-2026-45304 | LOW | 0.7% | 5.4.52 | Symfony's YAML Parser Vulnerable to Exponential Memory Allocation via Recursive Collection-Alias Expansion ("Billion Laughs") |
| symfony/yaml dev | ^5.4 || ^6.0 || ^7.0 || ^8.0 | CVE-2026-45305 | LOW | 0.7% | 5.4.52 | Symfony's YAML Parser has a ReDoS via Catastrophic Backtracking in Parser::cleanup() Regex |
| symfony/yaml dev | ^5.4 || ^6.0 || ^7.0 || ^8.0 | CVE-2026-45133 | LOW | 0.6% | 5.4.52 | Symfony hardened the parser when handling untrusted input |
| symfony/cache dev | ^5.4 || ^6.0 || ^7.0 || ^8.0 | CVE-2026-45073 | MODERATE | 0.5% | 5.4.52 | Symfony Vulnerable to SQL Injection in PdoAdapter::doClear() via Unsanitized $prefix |
| symfony/process dev | ^5.4 || ^6.0 || ^7.0 || ^8.0 | CVE-2024-51736 | HIGH | 0.4% | 5.4.46 | Symfony vulnerable to command execution hijack on Windows with Process class |
| doctrine/orm dev | ^2.13 || ^3 | CVE-2015-5723 | HIGH | 0.4% | 2.5.1 | Doctrine Security Misconfiguration Vulnerability |
| phpunit/phpunit dev | ^10.3 || ^11.0 || ^12.0 | CVE-2026-24765 | HIGH | 0.3% | 8.5.52 | PHPUnit Vulnerable to Unsafe Deserialization in PHPT Code Coverage Handling |
| symfony/process dev | ^5.4 || ^6.0 || ^7.0 || ^8.0 | CVE-2026-24739 | MODERATE | 0.2% | 5.4.51 | Symfony's incorrect argument escaping under MSYS2/Git Bash can lead to destructive file operations on Windows |
| phpunit/phpunit dev | ^10.3 || ^11.0 || ^12.0 | CVE-2026-41570 | HIGH | 0.2% | 12.5.22 | PHPUnit has Argument injection via newline in PHP INI values that are forwarded to child processes |
| doctrine/orm dev | ^2.13 || ^3 | GHSA-6q9v-4hq6-5m67 | CRITICAL | — | 2.0.3 | Doctrine SQL injection vulnerability |
| doctrine/dbal | ^3.6 || ^4 | GHSA-76w8-mqx4-wjrf | HIGH | — | 2.0.8 | Doctrine DBAL SQL injection possibility |
| doctrine/orm dev | ^2.13 || ^3 | GHSA-vjrg-wpm8-rhrw | HIGH | — | 2.8.4 | doctrine/orm Regression in Query Parenthesis can have Security Implications |
| phpunit/phpunit dev | ^10.3 || ^11.0 || ^12.0 | GHSA-mh6w-vxff-9wqp | HIGH | — | 12.5.22 | PHPUnit: Argument injection via newline in PHP INI values forwarded to child processes |
| phpunit/phpunit dev | ^10.3 || ^11.0 || ^12.0 | CVE-2017-9841 | KEV CRITICAL | 100.0% | 4.8.28 | Code Injection in PHPUnit |
SBOM summary
22 direct dependencies scanned (0 pinned to exact versions) from composer.json. Vulnerability data: OSV.dev · exploitation status: CISA KEV · exploit probability: FIRST EPSS. Findings on unpinned dependencies cover the full constraint range and may not apply to the exact version deployed.
Using ENISA's CRA Maturity Assessment Model for SMEs? This snapshot provides evidence for the Vulnerability Management domain and the product-level technical documentation question (1.3) under Governance & Documentation.
This snapshot is an automated readiness assessment, not legal advice and not a conformity assessment under the CRA.