CRAIR CRA Readiness Snapshot

symfony/console · composer.json · 17 Sep 2026, 06:11 UTC
0 days until the EU Cyber Resilience Act 24-hour reporting obligation applies (11 September 2026), including for products already on the market.
20
dependencies in scope
32
known vulnerabilities
0
actively exploited (CISA KEV)
58.1%
highest exploit probability (EPSS)

What you would have to assess for ENISA reporting tomorrow

No dependency in this snapshot currently appears in CISA's Known Exploited Vulnerabilities catalog. Today, nothing would trigger the 24-hour early-warning obligation of CRA Art. 14. That can change any day a new KEV entry lands, which is exactly what continuous monitoring is for.

⚠ No lockfile — SBOM is not reproducible

This scan is based on a manifest (composer.json), not a lockfile. 20 of 20 dependencies are version ranges, so the exact shipped versions — and their transitive dependencies — cannot be verified. Under the CRA's full obligations (11 December 2027) you must produce a machine-readable SBOM of what you actually ship. Committing a lockfile is the single highest-impact fix in this report.

All findings (32)

PackageVersionAdvisorySeverityEPSSFixed inSummary
symfony/http-foundation dev ^7.4|^8.0 CVE-2018-14773 MODERATE 58.1% 2.7.49 Symfony HTTP Foundation web cache poisoning
symfony/http-kernel dev ^7.4|^8.0 CVE-2015-4050 MODERATE 8.2% 2.3.29 Symfony Incorrect Access Control
symfony/dependency-injection dev ^8.2 CVE-2019-10910 CRITICAL 5.9% 2.7.51 Symfony Service IDs Allow Injection
symfony/http-kernel dev ^7.4|^8.0 CVE-2022-24894 MODERATE 4.0% 4.4.50 Symfony storing cookie headers in HttpCache
symfony/http-kernel dev ^7.4|^8.0 CVE-2020-15094 HIGH 3.0% 4.4.13 RCE in Symfony
symfony/http-foundation dev ^7.4|^8.0 CVE-2013-4752 MODERATE 2.3% 2.0.24 Symfony Host Header Injection vulnerability in the HttpFoundation component
symfony/http-foundation dev ^7.4|^8.0 CVE-2019-18888 HIGH 2.2% 2.8.52 Argument injection in a MimeTypeGuesser in Symfony
symfony/mime dev ^7.4|^8.0 CVE-2019-18888 HIGH 2.2% 4.3.8 Argument injection in a MimeTypeGuesser in Symfony
symfony/http-foundation dev ^7.4|^8.0 CVE-2012-6431 MODERATE 1.9% 2.0.19 Symfony Allows URI Restrictions Bypass Via Double-Encoded String
symfony/http-foundation dev ^7.4|^8.0 CVE-2019-10913 CRITICAL 1.9% 2.7.51 Invalid HTTP method overrides allow possible XSS or other attacks in Symfony
symfony/http-foundation dev ^7.4|^8.0 CVE-2018-11386 MODERATE 1.6% 2.7.48 Symfony DoS
symfony/validator dev ^7.4|^8.0 CVE-2013-4751 HIGH 1.4% 2.0.24 Symfony collectionCascaded and collectionCascadedDeeply fields security bypass
symfony/http-kernel dev ^7.4|^8.0 CVE-2015-2308 MODERATE 1.4% 2.3.27 Symfony Vulnerable to PHP Eval Injection
symfony/http-kernel dev ^7.4|^8.0 CVE-2019-18887 HIGH 1.3% 2.8.52 Symfony Http-Kernel has non-constant time comparison in UriSigner
symfony/http-foundation dev ^7.4|^8.0 CVE-2025-64500 HIGH 1.3% 5.4.50 Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass
symfony/http-foundation dev ^7.4|^8.0 CVE-2020-5255 LOW 1.3% 4.4.7 Prevent cache poisoning via a Response Content-Type header in Symfony
symfony/http-kernel dev ^7.4|^8.0 CVE-2021-41267 MODERATE 1.2% 5.3.12 Webcache Poisoning in symfony/http-kernel
symfony/mime dev ^7.4|^8.0 CVE-2026-45067 HIGH 0.6% 5.4.52 Symfony has Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address
symfony/http-foundation dev ^7.4|^8.0 CVE-2026-48736 MODERATE 0.6% 6.4.41 Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpCli...
symfony/http-foundation dev ^7.4|^8.0 CVE-2024-50345 LOW 0.6% 5.4.46 Symfony vulnerable to open redirect via browser-sanitized URLs
symfony/validator dev ^7.4|^8.0 CVE-2024-50343 LOW 0.5% 5.4.43 Symfony has an incorrect response from Validator when input ends with `\n`
symfony/http-kernel dev ^7.4|^8.0 CVE-2026-45075 HIGH 0.4% 7.4.12 Symfony's HEAD Request Bypasses methods: ['GET'] Filter in #[IsGranted] / #[IsSignatureValid] / #[IsCsrfTokenValid]
symfony/process dev ^7.4|^8.0 CVE-2024-51736 HIGH 0.4% 5.4.46 Symfony vulnerable to command execution hijack on Windows with Process class
symfony/mime dev ^7.4|^8.0 CVE-2026-45070 MODERATE 0.4% 5.4.52 Symfony has Email Header Injection via Non-Token Characters in Mime Parameter Names
symfony/process dev ^7.4|^8.0 CVE-2026-24739 MODERATE 0.2% 5.4.51 Symfony's incorrect argument escaping under MSYS2/Git Bash can lead to destructive file operations on Windows
symfony/dependency-injection dev ^8.2 GHSA-c636-cg5r-2498 HIGH 2.0.17 Symfony XML Entity Expansion security vulnerability
symfony/http-foundation dev ^7.4|^8.0 CVE-2014-5244 HIGH 2.3.19 Symfony vulnerable to denial of service via a malicious HTTP Host header
symfony/http-kernel dev ^7.4|^8.0 CVE-2014-5245 HIGH 2.3.19 Symfony allows direct access of ESI URLs behind a trusted proxy
symfony/validator dev ^7.4|^8.0 GHSA-4vf2-qfg3-7598 HIGH 2.0.17 symfony/validator XML Entity Expansion vulnerability
symfony/http-foundation dev ^7.4|^8.0 CVE-2014-6061 MODERATE 2.3.19 Symfony has a security issue when parsing the Authorization header

+ 2 further findings (mostly lower severity) — available in the full export.

SBOM summary

20 direct dependencies scanned (0 pinned to exact versions) from composer.json. Vulnerability data: OSV.dev · exploitation status: CISA KEV · exploit probability: FIRST EPSS. Findings on unpinned dependencies cover the full constraint range and may not apply to the exact version deployed.

Using ENISA's CRA Maturity Assessment Model for SMEs? This snapshot provides evidence for the Vulnerability Management domain and the product-level technical documentation question (1.3) under Governance & Documentation.

This snapshot is an automated readiness assessment, not legal advice and not a conformity assessment under the CRA.

Download SBOM (CycloneDX) Want this to watch your product continuously and draft the ENISA report the day something turns exploited? Start monitoring for €99/mo Talk to us