CRAIR CRA Readiness Snapshot

barryvdh/laravel-dompdf · composer.json · 5 Sep 2026, 02:12 UTC
0 days until the EU Cyber Resilience Act 24-hour reporting obligation applies (11 September 2026), including for products already on the market.
6
dependencies in scope
23
known vulnerabilities
0
actively exploited (CISA KEV)
82.4%
highest exploit probability (EPSS)

What you would have to assess for ENISA reporting tomorrow

No dependency in this snapshot currently appears in CISA's Known Exploited Vulnerabilities catalog. Today, nothing would trigger the 24-hour early-warning obligation of CRA Art. 14. That can change any day a new KEV entry lands, which is exactly what continuous monitoring is for.

⚠ No lockfile — SBOM is not reproducible

This scan is based on a manifest (composer.json), not a lockfile. 6 of 6 dependencies are version ranges, so the exact shipped versions — and their transitive dependencies — cannot be verified. Under the CRA's full obligations (11 December 2027) you must produce a machine-readable SBOM of what you actually ship. Committing a lockfile is the single highest-impact fix in this report.

All findings (23)

PackageVersionAdvisorySeverityEPSSFixed inSummary
dompdf/dompdf ^3.1 CVE-2022-28368 CRITICAL 82.4% 1.2.1 Remote code injection in dompdf/dompdf
dompdf/dompdf ^3.1 CVE-2014-2383 MODERATE 39.2% 0.6.1 DOMPDF Arbitrary File Read
dompdf/dompdf ^3.1 CVE-2010-4879 HIGH 5.2% 0.6.1 DOMPDF Remote File Inclusion Vulnerability
dompdf/dompdf ^3.1 CVE-2022-41343 HIGH 4.7% 2.0.1 Dompdf allows remote file inclusion because URI validation failure does not halt font registration
dompdf/dompdf ^3.1 CVE-2014-5013 HIGH 4.5% 0.6.2 DOMPDF Remote Code Execution
dompdf/dompdf ^3.1 CVE-2023-23924 CRITICAL 3.6% 2.0.2 Dompdf vulnerable to URI validation failure on SVG parsing
dompdf/dompdf ^3.1 CVE-2023-24813 CRITICAL 2.5% 2.0.3 URI validation failure on SVG parsing. Bypass of CVE-2023-23924
dompdf/dompdf ^3.1 CVE-2014-5011 MODERATE 1.5% 0.6.2 DOMPDF Information Disclosure
dompdf/dompdf ^3.1 CVE-2023-50262 MODERATE 1.5% 2.0.4 Denial of service caused by infinite recursion when parsing SVG images
dompdf/dompdf ^3.1 CVE-2021-3838 CRITICAL 1.4% 2.0.0 Deserialization of Untrusted Data in dompdf/dompdf
dompdf/dompdf ^3.1 CVE-2014-5012 MODERATE 1.2% 0.6.2 DOMPDF denial of service vulnerability
dompdf/dompdf ^3.1 CVE-2022-2400 MODERATE 1.2% 2.0.0 Dompdf before v2.0.0 vulnerable to chroot check bypass
dompdf/dompdf ^3.1 CVE-2022-0085 MODERATE 1.0% 2.0.0 Server-Side Request Forgery in dompdf/dompdf
dompdf/dompdf ^3.1 CVE-2021-3902 CRITICAL 1.0% 2.0.0 Improper Restriction of XML External Entity Reference in dompdf/dompdf
dompdf/dompdf ^3.1 CVE-2026-59942 MODERATE 0.7% 3.1.6 Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
squizlabs/php_codesniffer dev ^3.5 CVE-2026-67434 HIGH 0.7% 3.13.6 PHP_CodeSniffer gitblame report command injection via crafted filename
dompdf/dompdf ^3.1 CVE-2026-59941 MODERATE 0.5% 3.1.6 Dompdf: Uncontrolled resource consumption based on declared BMP dimensions
dompdf/dompdf ^3.1 CVE-2026-55555 LOW 0.4% 3.1.6 Dompdf: File existence oracle via font-face stylesheet declaration
dompdf/dompdf ^3.1 CVE-2026-56722 MODERATE 0.3% 3.1.6 Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI
dompdf/dompdf ^3.1 CVE-2026-55554 LOW 0.3% 3.1.6 Dompdf: Chroot Validation Bypass
dompdf/dompdf ^3.1 CVE-2026-59943 MODERATE 0.3% 3.1.6 Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem
squizlabs/php_codesniffer dev ^3.5 GHSA-3988-h75v-hwf6 HIGH 3.0.1 Arbitrary shell execution
squizlabs/php_codesniffer dev ^3.5 GHSA-mhfv-8rc9-w38c HIGH 2.8.1 Arbitrary shell execution

SBOM summary

6 direct dependencies scanned (0 pinned to exact versions) from composer.json. Vulnerability data: OSV.dev · exploitation status: CISA KEV · exploit probability: FIRST EPSS. Findings on unpinned dependencies cover the full constraint range and may not apply to the exact version deployed.

Using ENISA's CRA Maturity Assessment Model for SMEs? This snapshot provides evidence for the Vulnerability Management domain and the product-level technical documentation question (1.3) under Governance & Documentation.

This snapshot is an automated readiness assessment, not legal advice and not a conformity assessment under the CRA.

Download SBOM (CycloneDX) Want this to watch your product continuously and draft the ENISA report the day something turns exploited? Start monitoring for €99/mo Talk to us