CRAIR CRA Readiness Snapshot

laravel/telescope · package-lock.json + composer.json · 14 Sep 2026, 17:11 UTC
0 days until the EU Cyber Resilience Act 24-hour reporting obligation applies (11 September 2026), including for products already on the market.
151
dependencies in scope
46
known vulnerabilities
1
actively exploited (CISA KEV)
76.8%
highest exploit probability (EPSS)

What you would have to assess for ENISA reporting tomorrow

From 11 September 2026, an actively exploited vulnerability in software you ship must be reported to ENISA within 24 hours of awareness (CRA Art. 14). In this snapshot, 1 finding is in the CISA KEV catalog:

PackageYour versionCVEFixed inExploit context
laravel/framework ^8.37|^9.0|^10.0|^11.0|^12.0|^13.0 (unpinned) CVE-2018-15133 5.6.30 KEV listed 2024-01-16

⚠ No lockfile — SBOM is not reproducible

This scan is based on a manifest (package-lock.json, composer.json), not a lockfile. 8 of 151 dependencies are version ranges, so the exact shipped versions — and their transitive dependencies — cannot be verified. Under the CRA's full obligations (11 December 2027) you must produce a machine-readable SBOM of what you actually ship. Committing a lockfile is the single highest-impact fix in this report.

All findings (46)

PackageVersionAdvisorySeverityEPSSFixed inSummary
guzzlehttp/guzzle dev ^6.0|^7.0|^8.0 CVE-2016-5385 HIGH 50.4% 6.2.1 HTTP Proxy header vulnerability
laravel/framework ^8.37|^9.0|^10.0|^11.0|^12.0|^13.0 CVE-2024-52301 HIGH 44.8% 6.20.45 Laravel environment manipulation via query string
laravel/framework ^8.37|^9.0|^10.0|^11.0|^12.0|^13.0 CVE-2020-19316 HIGH 2.5% 5.8.17 OS Command Injection in Laravel Framework
guzzlehttp/guzzle dev ^6.0|^7.0|^8.0 CVE-2022-31090 HIGH 1.9% 6.5.8 CURLOPT_HTTPAUTH option not cleared on change of origin
guzzlehttp/guzzle dev ^6.0|^7.0|^8.0 CVE-2022-31042 HIGH 1.9% 6.5.7 Failure to strip the Cookie header on change in host or HTTP downgrade
guzzlehttp/guzzle dev ^6.0|^7.0|^8.0 CVE-2022-31042 HIGH 1.9% 6.5.7 Fix failure to strip Authorization header on HTTP downgrade
laravel/framework ^8.37|^9.0|^10.0|^11.0|^12.0|^13.0 CVE-2021-21263 HIGH 1.6% 8.22.1 Query Binding Exploitation
guzzlehttp/guzzle dev ^6.0|^7.0|^8.0 CVE-2022-31091 HIGH 1.5% 6.5.8 Change in port should be considered a change in origin
guzzlehttp/guzzle dev ^6.0|^7.0|^8.0 CVE-2022-29248 HIGH 1.3% 6.5.6 Cross-domain cookie leakage in Guzzle
laravel/framework ^8.37|^9.0|^10.0|^11.0|^12.0|^13.0 CVE-2017-14775 MODERATE 1.2% 5.5.10 Laravel Sensitive Data Exposure
laravel/framework ^8.37|^9.0|^10.0|^11.0|^12.0|^13.0 CVE-2020-24941 HIGH 1.1% 6.18.35 Improper Input Validation in Laravel
laravel/framework ^8.37|^9.0|^10.0|^11.0|^12.0|^13.0 CVE-2017-9303 MODERATE 1.0% 5.4.22 Laravel does not properly constrain the host portion of a password-reset URL
vite dev 5.4.21 CVE-2026-39365 MODERATE 0.9% 8.0.5 Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling
laravel/framework ^8.37|^9.0|^10.0|^11.0|^12.0|^13.0 CVE-2021-43808 MODERATE 0.8% 6.20.42 Laravel Framework XSS in Blade templating engine
laravel/framework ^8.37|^9.0|^10.0|^11.0|^12.0|^13.0 CVE-2025-27515 MODERATE 0.7% 12.1.1 Laravel has a File Validation Bypass
laravel/framework ^8.37|^9.0|^10.0|^11.0|^12.0|^13.0 CVE-2026-48019 HIGH 0.7% 13.10.0 Laravel Framework: CRLF injection in default email rule
laravel/framework ^8.37|^9.0|^10.0|^11.0|^12.0|^13.0 CVE-2024-13918 MODERATE 0.6% 11.36.0 Laravel framework susceptible to reflected cross-site scripting
vite dev 5.4.21 CVE-2026-53571 HIGH 0.6% 8.0.16 vite: `server.fs.deny` bypass on Windows alternate paths
vue dev 2.7.16 CVE-2024-9506 LOW 0.5% 3.0.0-alpha.0 ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function
laravel/framework ^8.37|^9.0|^10.0|^11.0|^12.0|^13.0 CVE-2024-13919 MODERATE 0.5% 11.36.0 Laravel framework susceptible to reflected cross-site scripting
vite dev 5.4.21 CVE-2026-53632 MODERATE 0.4% 8.0.16 launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
nanoid dev 3.3.16 CVE-2026-67213 HIGH 0.3% 3.3.18 nanoid: custom generators can loop indefinitely when size is zero
guzzlehttp/guzzle dev ^6.0|^7.0|^8.0 CVE-2026-67354 MODERATE 0.3% 7.15.1 Guzzle: URI fragments disclosed in redirect Referer headers
guzzlehttp/guzzle dev ^6.0|^7.0|^8.0 CVE-2026-67353 MODERATE 0.2% 7.15.1 Guzzle: Unbounded response cookies risk denial of service
guzzlehttp/guzzle dev ^6.0|^7.0|^8.0 CVE-2026-67339 MODERATE 0.2% 7.14.2 Guzzle: Proxy-Authorization headers can be sent to origin servers
guzzlehttp/guzzle dev ^6.0|^7.0|^8.0 CVE-2026-67355 MODERATE 0.2% 7.15.1 Guzzle: Host-only cookie scope is not preserved
guzzlehttp/guzzle dev ^6.0|^7.0|^8.0 CVE-2026-69246 HIGH 0.2% 7.15.2 Guzzle: Noncanonical host can bypass host-based checks
guzzlehttp/guzzle dev ^6.0|^7.0|^8.0 CVE-2026-55767 MODERATE 0.2% 7.12.1 guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts
guzzlehttp/guzzle dev ^6.0|^7.0|^8.0 CVE-2026-59883 MODERATE 0.2% 7.12.3 Guzzle: Cookie Disclosure and Injection via IP-Address Domains
guzzlehttp/guzzle dev ^6.0|^7.0|^8.0 CVE-2026-55568 MODERATE 0.1% 7.12.1 guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext

+ 16 further findings (mostly lower severity) — available in the full export.

SBOM summary

151 direct dependencies scanned (143 pinned to exact versions) from package-lock.json, composer.json. Vulnerability data: OSV.dev · exploitation status: CISA KEV · exploit probability: FIRST EPSS. Findings on unpinned dependencies cover the full constraint range and may not apply to the exact version deployed.

Using ENISA's CRA Maturity Assessment Model for SMEs? This snapshot provides evidence for the Vulnerability Management domain and the product-level technical documentation question (1.3) under Governance & Documentation.

This snapshot is an automated readiness assessment, not legal advice and not a conformity assessment under the CRA.

Download SBOM (CycloneDX) Want this to watch your product continuously and draft the ENISA report the day something turns exploited? Start monitoring for €99/mo Talk to us