CRA Readiness Snapshot
What you would have to assess for ENISA reporting tomorrow
No dependency in this snapshot currently appears in CISA's Known Exploited Vulnerabilities catalog. Today, nothing would trigger the 24-hour early-warning obligation of CRA Art. 14. That can change any day a new KEV entry lands, which is exactly what continuous monitoring is for.
All findings (37)
| Package | Version | Advisory | Severity | EPSS | Fixed in | Summary |
|---|---|---|---|---|---|---|
| symfony/http-foundation | 7.2.3 | CVE-2025-64500 | HIGH | 1.3% | 5.4.50 | Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass |
| symfony/yaml dev | 7.2.3 | CVE-2026-45304 | LOW | 0.7% | 5.4.52 | Symfony's YAML Parser Vulnerable to Exponential Memory Allocation via Recursive Collection-Alias Expansion ("Billion Laughs") |
| symfony/yaml dev | 7.2.3 | CVE-2026-45305 | LOW | 0.7% | 5.4.52 | Symfony's YAML Parser has a ReDoS via Catastrophic Backtracking in Parser::cleanup() Regex |
| symfony/yaml dev | 7.2.3 | CVE-2026-45133 | LOW | 0.6% | 5.4.52 | Symfony hardened the parser when handling untrusted input |
| symfony/mime | 7.2.4 | CVE-2026-45067 | HIGH | 0.6% | 5.4.52 | Symfony has Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address |
| symfony/http-foundation | 7.2.3 | CVE-2026-48736 | MODERATE | 0.6% | 6.4.41 | Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpCli... |
| symfony/polyfill-intl-idn | 1.31.0 | CVE-2026-46644 | LOW | 0.5% | 1.38.1 | symfony/polyfill-intl-idn: xn-- labels with ASCII-only Punycode payloads are treated as equivalent to their decoded form |
| symfony/mailer | 7.2.3 | CVE-2026-45068 | MODERATE | 0.5% | 5.4.52 | Symfony has an Argument Injection in SendmailTransport via Dash-Prefixed Recipient Address |
| symfony/mime | 7.2.4 | CVE-2026-45070 | MODERATE | 0.4% | 5.4.52 | Symfony has Email Header Injection via Non-Token Characters in Mime Parameter Names |
| league/commonmark | 2.6.1 | CVE-2025-46734 | MODERATE | 0.4% | 2.7.0 | league/commonmark contains a XSS vulnerability in Attributes extension |
| phpunit/phpunit dev | 11.5.13 | CVE-2026-24765 | HIGH | 0.3% | 8.5.52 | PHPUnit Vulnerable to Unsafe Deserialization in PHPT Code Coverage Handling |
| symfony/routing | 7.2.3 | CVE-2026-45065 | MODERATE | 0.3% | 5.4.52 | Symfony has a UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation → Off-Site //host URL Injection |
| symfony/routing | 7.2.3 | CVE-2026-48784 | MODERATE | 0.3% | 5.4.53 | Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 Normal... |
| league/commonmark | 2.6.1 | CVE-2026-71488 | HIGH | 0.3% | 2.9.0 | league/commonmark: Quadratic-time denial of service when parsing crafted Markdown |
| guzzlehttp/psr7 | 2.7.0 | CVE-2026-59882 | MODERATE | 0.3% | 2.12.3 | guzzlehttp/psr7: Host Confusion via Weak URI Host Validation |
| psy/psysh dev | 0.12.8 | CVE-2026-25129 | MODERATE | 0.3% | 0.12.19 | PsySH has Local Privilege Escalation via CWD .psysh.php auto-load |
| guzzlehttp/guzzle | 7.9.2 | CVE-2026-67354 | MODERATE | 0.3% | 7.15.1 | Guzzle: URI fragments disclosed in redirect Referer headers |
| guzzlehttp/guzzle | 7.9.2 | CVE-2026-67353 | MODERATE | 0.2% | 7.15.1 | Guzzle: Unbounded response cookies risk denial of service |
| league/commonmark | 2.6.1 | CVE-2026-33347 | MODERATE | 0.2% | 2.8.2 | league/commonmark has an embed extension allowed_domains bypass |
| guzzlehttp/guzzle | 7.9.2 | CVE-2026-67339 | MODERATE | 0.2% | 7.14.2 | Guzzle: Proxy-Authorization headers can be sent to origin servers |
| guzzlehttp/guzzle | 7.9.2 | CVE-2026-67355 | MODERATE | 0.2% | 7.15.1 | Guzzle: Host-only cookie scope is not preserved |
| guzzlehttp/psr7 | 2.7.0 | CVE-2026-55766 | MODERATE | 0.2% | 2.12.1 | guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization |
| league/commonmark | 2.6.1 | CVE-2026-30838 | MODERATE | 0.2% | 2.8.1 | CommonMark has DisallowedRawHtml extension bypass via whitespace in HTML tag names |
| guzzlehttp/guzzle | 7.9.2 | CVE-2026-69246 | HIGH | 0.2% | 7.15.2 | Guzzle: Noncanonical host can bypass host-based checks |
| guzzlehttp/guzzle | 7.9.2 | CVE-2026-55767 | MODERATE | 0.2% | 7.12.1 | guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts |
| league/commonmark | 2.6.1 | CVE-2026-71478 | MODERATE | 0.2% | 2.9.0 | league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes |
| guzzlehttp/psr7 | 2.7.0 | CVE-2026-48998 | MODERATE | 0.2% | 2.10.2 | guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation |
| guzzlehttp/psr7 | 2.7.0 | CVE-2026-49214 | MODERATE | 0.2% | 2.10.2 | guzzlehttp/psr7 has CRLF Injection via URI Host Component |
| guzzlehttp/guzzle | 7.9.2 | CVE-2026-59883 | MODERATE | 0.2% | 7.12.3 | Guzzle: Cookie Disclosure and Injection via IP-Address Domains |
| guzzlehttp/guzzle | 7.9.2 | CVE-2026-55568 | MODERATE | 0.1% | 7.12.1 | guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext |
+ 7 further findings (mostly lower severity) — available in the full export.
SBOM summary
120 direct dependencies scanned (120 pinned to exact versions) from composer.lock. Vulnerability data: OSV.dev · exploitation status: CISA KEV · exploit probability: FIRST EPSS. Findings on unpinned dependencies cover the full constraint range and may not apply to the exact version deployed.
Using ENISA's CRA Maturity Assessment Model for SMEs? This snapshot provides evidence for the Vulnerability Management domain and the product-level technical documentation question (1.3) under Governance & Documentation.
This snapshot is an automated readiness assessment, not legal advice and not a conformity assessment under the CRA.