CRA Readiness Snapshot
What you would have to assess for ENISA reporting tomorrow
No dependency in this snapshot currently appears in CISA's Known Exploited Vulnerabilities catalog. Today, nothing would trigger the 24-hour early-warning obligation of CRA Art. 14. That can change any day a new KEV entry lands, which is exactly what continuous monitoring is for.
All findings (56)
| Package | Version | Advisory | Severity | EPSS | Fixed in | Summary |
|---|---|---|---|---|---|---|
| ajv | 6.10.0 | CVE-2020-15366 | MODERATE | 2.3% | 6.12.3 | Prototype Pollution in Ajv |
| quill | 1.3.7 | CVE-2021-3163 | MODERATE | 1.3% | — | Cross-site Scripting in quill |
| plank/laravel-mediable | 5.9.1 | CVE-2026-49970 | HIGH | 1.0% | 7.0.0 | Laravel-Mediable: path traversal vulnerability in the File::sanitizePath() |
| webpack dev | 5.88.2 | CVE-2024-43788 | MODERATE | 1.0% | 5.94.0 | Webpack's AutoPublicPathRuntimeModule has a DOM Clobbering Gadget that leads to XSS |
| cross-spawn dev | 5.1.0 | CVE-2024-21538 | HIGH | 0.9% | 7.0.5 | Regular Expression Denial of Service (ReDoS) in cross-spawn |
| dompdf/dompdf | 2.0.8 | CVE-2026-59942 | MODERATE | 0.7% | 3.1.6 | Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps |
| laravel/framework | 10.50.3 | CVE-2026-48019 | HIGH | 0.7% | 13.10.0 | Laravel Framework: CRLF injection in default email rule |
| tar dev | 6.2.1 | CVE-2026-59871 | MODERATE | 0.6% | 7.5.18 | node-tar: Process crash via PAX numeric path type confusion |
| mathjs | 14.9.1 | CVE-2026-41139 | HIGH | 0.6% | 15.2.0 | mathjs Allows Improperly Controlled Modification of Dynamically-Determined Object Attributes |
| webpack-dev-server dev | 4.15.2 | CVE-2025-30359 | MODERATE | 0.6% | 5.2.1 | webpack-dev-server users' source code may be stolen when they access a malicious web site |
| tar dev | 6.2.1 | CVE-2026-59873 | CRITICAL | 0.6% | 7.5.19 | node-tar: Decompression/parse DoS via unlimited input |
| @babel/runtime | 7.2.0 | CVE-2025-27789 | MODERATE | 0.6% | 7.26.10 | Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups |
| @babel/runtime | 7.1.2 | CVE-2025-27789 | MODERATE | 0.6% | 7.26.10 | Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups |
| @babel/runtime | 7.3.4 | CVE-2025-27789 | MODERATE | 0.6% | 7.26.10 | Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups |
| mathjs | 14.9.1 | CVE-2026-40897 | HIGH | 0.6% | 15.2.0 | Unsafe object property setter in mathjs |
| tar dev | 6.2.1 | CVE-2026-24842 | HIGH | 0.5% | 7.5.7 | node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal |
| vue | 2.7.16 | CVE-2024-9506 | LOW | 0.5% | 3.0.0-alpha.0 | ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function |
| webpack-dev-server dev | 4.15.2 | CVE-2026-14620 | MODERATE | 0.5% | 5.2.6 | webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints |
| minimatch dev | 3.0.8 | CVE-2026-26996 | HIGH | 0.5% | 10.2.1 | minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern |
| minimatch dev | 3.0.8 | CVE-2026-27903 | HIGH | 0.5% | 10.2.3 | minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments |
| webpack-dev-server dev | 4.15.2 | CVE-2026-14631 | MODERATE | 0.5% | 5.2.6 | webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header |
| dompdf/dompdf | 2.0.8 | CVE-2026-59941 | MODERATE | 0.5% | 3.1.6 | Dompdf: Uncontrolled resource consumption based on declared BMP dimensions |
| tar dev | 6.2.1 | CVE-2026-59875 | MODERATE | 0.5% | 7.5.17 | node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records |
| vue-template-compiler dev | 2.7.16 | CVE-2024-6783 | MODERATE | 0.5% | — | vue-template-compiler vulnerable to client-side Cross-Site Scripting (XSS) |
| ajv | 6.10.0 | CVE-2025-69873 | MODERATE | 0.5% | 8.18.0 | ajv has ReDoS when using `$data` option |
| minimatch dev | 3.0.8 | CVE-2026-27904 | HIGH | 0.5% | 10.2.3 | minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions |
| serialize-javascript dev | 6.0.2 | CVE-2026-34043 | MODERATE | 0.5% | 7.0.5 | Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects |
| tar dev | 6.2.1 | CVE-2026-29786 | HIGH | 0.4% | 7.5.10 | tar has Hardlink Path Traversal via Drive-Relative Linkpath |
| tar dev | 6.2.1 | CVE-2026-59874 | HIGH | 0.4% | 7.5.18 | node-tar: Negative tar entry size causes infinite loop in archive replace |
| swiper | 9.4.1 | CVE-2026-27212 | CRITICAL | 0.4% | 12.1.2 | Prototype pollution in swiper |
+ 26 further findings (mostly lower severity) — available in the full export.
SBOM summary
1661 direct dependencies scanned (1661 pinned to exact versions) from composer.lock, package-lock.json. Vulnerability data: OSV.dev · exploitation status: CISA KEV · exploit probability: FIRST EPSS. Findings on unpinned dependencies cover the full constraint range and may not apply to the exact version deployed.
Using ENISA's CRA Maturity Assessment Model for SMEs? This snapshot provides evidence for the Vulnerability Management domain and the product-level technical documentation question (1.3) under Governance & Documentation.
This snapshot is an automated readiness assessment, not legal advice and not a conformity assessment under the CRA.