CRA Readiness Snapshot
What you would have to assess for ENISA reporting tomorrow
From 11 September 2026, an actively exploited vulnerability in software you ship must be reported to ENISA within 24 hours of awareness (CRA Art. 14). In this snapshot, 1 finding is in the CISA KEV catalog:
| Package | Your version | CVE | Fixed in | Exploit context |
|---|---|---|---|---|
| laravel/framework | ^8.37|^9.0|^10.0|^11.0|^12.0|^13.0 (unpinned) | CVE-2018-15133 | 5.6.30 | KEV listed 2024-01-16 |
⚠ No lockfile — SBOM is not reproducible
This scan is based on a manifest (package-lock.json, composer.json), not a lockfile. 8 of 151 dependencies are version ranges, so the exact shipped versions — and their transitive dependencies — cannot be verified. Under the CRA's full obligations (11 December 2027) you must produce a machine-readable SBOM of what you actually ship. Committing a lockfile is the single highest-impact fix in this report.
All findings (46)
| Package | Version | Advisory | Severity | EPSS | Fixed in | Summary |
|---|---|---|---|---|---|---|
| guzzlehttp/guzzle dev | ^6.0|^7.0|^8.0 | CVE-2016-5385 | HIGH | 50.4% | 6.2.1 | HTTP Proxy header vulnerability |
| laravel/framework | ^8.37|^9.0|^10.0|^11.0|^12.0|^13.0 | CVE-2024-52301 | HIGH | 44.8% | 6.20.45 | Laravel environment manipulation via query string |
| laravel/framework | ^8.37|^9.0|^10.0|^11.0|^12.0|^13.0 | CVE-2020-19316 | HIGH | 2.5% | 5.8.17 | OS Command Injection in Laravel Framework |
| guzzlehttp/guzzle dev | ^6.0|^7.0|^8.0 | CVE-2022-31090 | HIGH | 1.9% | 6.5.8 | CURLOPT_HTTPAUTH option not cleared on change of origin |
| guzzlehttp/guzzle dev | ^6.0|^7.0|^8.0 | CVE-2022-31042 | HIGH | 1.9% | 6.5.7 | Failure to strip the Cookie header on change in host or HTTP downgrade |
| guzzlehttp/guzzle dev | ^6.0|^7.0|^8.0 | CVE-2022-31042 | HIGH | 1.9% | 6.5.7 | Fix failure to strip Authorization header on HTTP downgrade |
| laravel/framework | ^8.37|^9.0|^10.0|^11.0|^12.0|^13.0 | CVE-2021-21263 | HIGH | 1.6% | 8.22.1 | Query Binding Exploitation |
| guzzlehttp/guzzle dev | ^6.0|^7.0|^8.0 | CVE-2022-31091 | HIGH | 1.5% | 6.5.8 | Change in port should be considered a change in origin |
| guzzlehttp/guzzle dev | ^6.0|^7.0|^8.0 | CVE-2022-29248 | HIGH | 1.3% | 6.5.6 | Cross-domain cookie leakage in Guzzle |
| laravel/framework | ^8.37|^9.0|^10.0|^11.0|^12.0|^13.0 | CVE-2017-14775 | MODERATE | 1.2% | 5.5.10 | Laravel Sensitive Data Exposure |
| laravel/framework | ^8.37|^9.0|^10.0|^11.0|^12.0|^13.0 | CVE-2020-24941 | HIGH | 1.1% | 6.18.35 | Improper Input Validation in Laravel |
| laravel/framework | ^8.37|^9.0|^10.0|^11.0|^12.0|^13.0 | CVE-2017-9303 | MODERATE | 1.0% | 5.4.22 | Laravel does not properly constrain the host portion of a password-reset URL |
| vite dev | 5.4.21 | CVE-2026-39365 | MODERATE | 0.9% | 8.0.5 | Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling |
| laravel/framework | ^8.37|^9.0|^10.0|^11.0|^12.0|^13.0 | CVE-2021-43808 | MODERATE | 0.8% | 6.20.42 | Laravel Framework XSS in Blade templating engine |
| laravel/framework | ^8.37|^9.0|^10.0|^11.0|^12.0|^13.0 | CVE-2025-27515 | MODERATE | 0.7% | 12.1.1 | Laravel has a File Validation Bypass |
| laravel/framework | ^8.37|^9.0|^10.0|^11.0|^12.0|^13.0 | CVE-2026-48019 | HIGH | 0.7% | 13.10.0 | Laravel Framework: CRLF injection in default email rule |
| laravel/framework | ^8.37|^9.0|^10.0|^11.0|^12.0|^13.0 | CVE-2024-13918 | MODERATE | 0.6% | 11.36.0 | Laravel framework susceptible to reflected cross-site scripting |
| vite dev | 5.4.21 | CVE-2026-53571 | HIGH | 0.6% | 8.0.16 | vite: `server.fs.deny` bypass on Windows alternate paths |
| vue dev | 2.7.16 | CVE-2024-9506 | LOW | 0.5% | 3.0.0-alpha.0 | ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function |
| laravel/framework | ^8.37|^9.0|^10.0|^11.0|^12.0|^13.0 | CVE-2024-13919 | MODERATE | 0.5% | 11.36.0 | Laravel framework susceptible to reflected cross-site scripting |
| vite dev | 5.4.21 | CVE-2026-53632 | MODERATE | 0.4% | 8.0.16 | launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows |
| nanoid dev | 3.3.16 | CVE-2026-67213 | HIGH | 0.3% | 3.3.18 | nanoid: custom generators can loop indefinitely when size is zero |
| guzzlehttp/guzzle dev | ^6.0|^7.0|^8.0 | CVE-2026-67354 | MODERATE | 0.3% | 7.15.1 | Guzzle: URI fragments disclosed in redirect Referer headers |
| guzzlehttp/guzzle dev | ^6.0|^7.0|^8.0 | CVE-2026-67353 | MODERATE | 0.2% | 7.15.1 | Guzzle: Unbounded response cookies risk denial of service |
| guzzlehttp/guzzle dev | ^6.0|^7.0|^8.0 | CVE-2026-67339 | MODERATE | 0.2% | 7.14.2 | Guzzle: Proxy-Authorization headers can be sent to origin servers |
| guzzlehttp/guzzle dev | ^6.0|^7.0|^8.0 | CVE-2026-67355 | MODERATE | 0.2% | 7.15.1 | Guzzle: Host-only cookie scope is not preserved |
| guzzlehttp/guzzle dev | ^6.0|^7.0|^8.0 | CVE-2026-69246 | HIGH | 0.2% | 7.15.2 | Guzzle: Noncanonical host can bypass host-based checks |
| guzzlehttp/guzzle dev | ^6.0|^7.0|^8.0 | CVE-2026-55767 | MODERATE | 0.2% | 7.12.1 | guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts |
| guzzlehttp/guzzle dev | ^6.0|^7.0|^8.0 | CVE-2026-59883 | MODERATE | 0.2% | 7.12.3 | Guzzle: Cookie Disclosure and Injection via IP-Address Domains |
| guzzlehttp/guzzle dev | ^6.0|^7.0|^8.0 | CVE-2026-55568 | MODERATE | 0.1% | 7.12.1 | guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext |
+ 16 further findings (mostly lower severity) — available in the full export.
SBOM summary
151 direct dependencies scanned (143 pinned to exact versions) from package-lock.json, composer.json. Vulnerability data: OSV.dev · exploitation status: CISA KEV · exploit probability: FIRST EPSS. Findings on unpinned dependencies cover the full constraint range and may not apply to the exact version deployed.
Using ENISA's CRA Maturity Assessment Model for SMEs? This snapshot provides evidence for the Vulnerability Management domain and the product-level technical documentation question (1.3) under Governance & Documentation.
This snapshot is an automated readiness assessment, not legal advice and not a conformity assessment under the CRA.