CRA Readiness Snapshot
What you would have to assess for ENISA reporting tomorrow
No dependency in this snapshot currently appears in CISA's Known Exploited Vulnerabilities catalog. Today, nothing would trigger the 24-hour early-warning obligation of CRA Art. 14. That can change any day a new KEV entry lands, which is exactly what continuous monitoring is for.
⚠ No lockfile — SBOM is not reproducible
This scan is based on a manifest (composer.json), not a lockfile. 20 of 20 dependencies are version ranges, so the exact shipped versions — and their transitive dependencies — cannot be verified. Under the CRA's full obligations (11 December 2027) you must produce a machine-readable SBOM of what you actually ship. Committing a lockfile is the single highest-impact fix in this report.
All findings (32)
| Package | Version | Advisory | Severity | EPSS | Fixed in | Summary |
|---|---|---|---|---|---|---|
| symfony/http-foundation dev | ^7.4|^8.0 | CVE-2018-14773 | MODERATE | 58.1% | 2.7.49 | Symfony HTTP Foundation web cache poisoning |
| symfony/http-kernel dev | ^7.4|^8.0 | CVE-2015-4050 | MODERATE | 8.2% | 2.3.29 | Symfony Incorrect Access Control |
| symfony/dependency-injection dev | ^8.2 | CVE-2019-10910 | CRITICAL | 5.9% | 2.7.51 | Symfony Service IDs Allow Injection |
| symfony/http-kernel dev | ^7.4|^8.0 | CVE-2022-24894 | MODERATE | 4.0% | 4.4.50 | Symfony storing cookie headers in HttpCache |
| symfony/http-kernel dev | ^7.4|^8.0 | CVE-2020-15094 | HIGH | 3.0% | 4.4.13 | RCE in Symfony |
| symfony/http-foundation dev | ^7.4|^8.0 | CVE-2013-4752 | MODERATE | 2.3% | 2.0.24 | Symfony Host Header Injection vulnerability in the HttpFoundation component |
| symfony/http-foundation dev | ^7.4|^8.0 | CVE-2019-18888 | HIGH | 2.2% | 2.8.52 | Argument injection in a MimeTypeGuesser in Symfony |
| symfony/mime dev | ^7.4|^8.0 | CVE-2019-18888 | HIGH | 2.2% | 4.3.8 | Argument injection in a MimeTypeGuesser in Symfony |
| symfony/http-foundation dev | ^7.4|^8.0 | CVE-2012-6431 | MODERATE | 1.9% | 2.0.19 | Symfony Allows URI Restrictions Bypass Via Double-Encoded String |
| symfony/http-foundation dev | ^7.4|^8.0 | CVE-2019-10913 | CRITICAL | 1.9% | 2.7.51 | Invalid HTTP method overrides allow possible XSS or other attacks in Symfony |
| symfony/http-foundation dev | ^7.4|^8.0 | CVE-2018-11386 | MODERATE | 1.6% | 2.7.48 | Symfony DoS |
| symfony/validator dev | ^7.4|^8.0 | CVE-2013-4751 | HIGH | 1.4% | 2.0.24 | Symfony collectionCascaded and collectionCascadedDeeply fields security bypass |
| symfony/http-kernel dev | ^7.4|^8.0 | CVE-2015-2308 | MODERATE | 1.4% | 2.3.27 | Symfony Vulnerable to PHP Eval Injection |
| symfony/http-kernel dev | ^7.4|^8.0 | CVE-2019-18887 | HIGH | 1.3% | 2.8.52 | Symfony Http-Kernel has non-constant time comparison in UriSigner |
| symfony/http-foundation dev | ^7.4|^8.0 | CVE-2025-64500 | HIGH | 1.3% | 5.4.50 | Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass |
| symfony/http-foundation dev | ^7.4|^8.0 | CVE-2020-5255 | LOW | 1.3% | 4.4.7 | Prevent cache poisoning via a Response Content-Type header in Symfony |
| symfony/http-kernel dev | ^7.4|^8.0 | CVE-2021-41267 | MODERATE | 1.2% | 5.3.12 | Webcache Poisoning in symfony/http-kernel |
| symfony/mime dev | ^7.4|^8.0 | CVE-2026-45067 | HIGH | 0.6% | 5.4.52 | Symfony has Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address |
| symfony/http-foundation dev | ^7.4|^8.0 | CVE-2026-48736 | MODERATE | 0.6% | 6.4.41 | Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpCli... |
| symfony/http-foundation dev | ^7.4|^8.0 | CVE-2024-50345 | LOW | 0.6% | 5.4.46 | Symfony vulnerable to open redirect via browser-sanitized URLs |
| symfony/validator dev | ^7.4|^8.0 | CVE-2024-50343 | LOW | 0.5% | 5.4.43 | Symfony has an incorrect response from Validator when input ends with `\n` |
| symfony/http-kernel dev | ^7.4|^8.0 | CVE-2026-45075 | HIGH | 0.4% | 7.4.12 | Symfony's HEAD Request Bypasses methods: ['GET'] Filter in #[IsGranted] / #[IsSignatureValid] / #[IsCsrfTokenValid] |
| symfony/process dev | ^7.4|^8.0 | CVE-2024-51736 | HIGH | 0.4% | 5.4.46 | Symfony vulnerable to command execution hijack on Windows with Process class |
| symfony/mime dev | ^7.4|^8.0 | CVE-2026-45070 | MODERATE | 0.4% | 5.4.52 | Symfony has Email Header Injection via Non-Token Characters in Mime Parameter Names |
| symfony/process dev | ^7.4|^8.0 | CVE-2026-24739 | MODERATE | 0.2% | 5.4.51 | Symfony's incorrect argument escaping under MSYS2/Git Bash can lead to destructive file operations on Windows |
| symfony/dependency-injection dev | ^8.2 | GHSA-c636-cg5r-2498 | HIGH | — | 2.0.17 | Symfony XML Entity Expansion security vulnerability |
| symfony/http-foundation dev | ^7.4|^8.0 | CVE-2014-5244 | HIGH | — | 2.3.19 | Symfony vulnerable to denial of service via a malicious HTTP Host header |
| symfony/http-kernel dev | ^7.4|^8.0 | CVE-2014-5245 | HIGH | — | 2.3.19 | Symfony allows direct access of ESI URLs behind a trusted proxy |
| symfony/validator dev | ^7.4|^8.0 | GHSA-4vf2-qfg3-7598 | HIGH | — | 2.0.17 | symfony/validator XML Entity Expansion vulnerability |
| symfony/http-foundation dev | ^7.4|^8.0 | CVE-2014-6061 | MODERATE | — | 2.3.19 | Symfony has a security issue when parsing the Authorization header |
+ 2 further findings (mostly lower severity) — available in the full export.
SBOM summary
20 direct dependencies scanned (0 pinned to exact versions) from composer.json. Vulnerability data: OSV.dev · exploitation status: CISA KEV · exploit probability: FIRST EPSS. Findings on unpinned dependencies cover the full constraint range and may not apply to the exact version deployed.
Using ENISA's CRA Maturity Assessment Model for SMEs? This snapshot provides evidence for the Vulnerability Management domain and the product-level technical documentation question (1.3) under Governance & Documentation.
This snapshot is an automated readiness assessment, not legal advice and not a conformity assessment under the CRA.