CRAIR CRA Readiness Snapshot

corcel/corcel · composer.lock · 1 Sep 2026, 17:10 UTC
0 days until the EU Cyber Resilience Act 24-hour reporting obligation applies (11 September 2026), including for products already on the market.
120
dependencies in scope
37
known vulnerabilities
0
actively exploited (CISA KEV)
1.3%
highest exploit probability (EPSS)

What you would have to assess for ENISA reporting tomorrow

No dependency in this snapshot currently appears in CISA's Known Exploited Vulnerabilities catalog. Today, nothing would trigger the 24-hour early-warning obligation of CRA Art. 14. That can change any day a new KEV entry lands, which is exactly what continuous monitoring is for.

All findings (37)

PackageVersionAdvisorySeverityEPSSFixed inSummary
symfony/http-foundation 7.2.3 CVE-2025-64500 HIGH 1.3% 5.4.50 Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass
symfony/yaml dev 7.2.3 CVE-2026-45304 LOW 0.7% 5.4.52 Symfony's YAML Parser Vulnerable to Exponential Memory Allocation via Recursive Collection-Alias Expansion ("Billion Laughs")
symfony/yaml dev 7.2.3 CVE-2026-45305 LOW 0.7% 5.4.52 Symfony's YAML Parser has a ReDoS via Catastrophic Backtracking in Parser::cleanup() Regex
symfony/yaml dev 7.2.3 CVE-2026-45133 LOW 0.6% 5.4.52 Symfony hardened the parser when handling untrusted input
symfony/mime 7.2.4 CVE-2026-45067 HIGH 0.6% 5.4.52 Symfony has Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address
symfony/http-foundation 7.2.3 CVE-2026-48736 MODERATE 0.6% 6.4.41 Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpCli...
symfony/polyfill-intl-idn 1.31.0 CVE-2026-46644 LOW 0.5% 1.38.1 symfony/polyfill-intl-idn: xn-- labels with ASCII-only Punycode payloads are treated as equivalent to their decoded form
symfony/mailer 7.2.3 CVE-2026-45068 MODERATE 0.5% 5.4.52 Symfony has an Argument Injection in SendmailTransport via Dash-Prefixed Recipient Address
symfony/mime 7.2.4 CVE-2026-45070 MODERATE 0.4% 5.4.52 Symfony has Email Header Injection via Non-Token Characters in Mime Parameter Names
league/commonmark 2.6.1 CVE-2025-46734 MODERATE 0.4% 2.7.0 league/commonmark contains a XSS vulnerability in Attributes extension
phpunit/phpunit dev 11.5.13 CVE-2026-24765 HIGH 0.3% 8.5.52 PHPUnit Vulnerable to Unsafe Deserialization in PHPT Code Coverage Handling
symfony/routing 7.2.3 CVE-2026-45065 MODERATE 0.3% 5.4.52 Symfony has a UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation → Off-Site //host URL Injection
symfony/routing 7.2.3 CVE-2026-48784 MODERATE 0.3% 5.4.53 Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 Normal...
league/commonmark 2.6.1 CVE-2026-71488 HIGH 0.3% 2.9.0 league/commonmark: Quadratic-time denial of service when parsing crafted Markdown
guzzlehttp/psr7 2.7.0 CVE-2026-59882 MODERATE 0.3% 2.12.3 guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
psy/psysh dev 0.12.8 CVE-2026-25129 MODERATE 0.3% 0.12.19 PsySH has Local Privilege Escalation via CWD .psysh.php auto-load
guzzlehttp/guzzle 7.9.2 CVE-2026-67354 MODERATE 0.3% 7.15.1 Guzzle: URI fragments disclosed in redirect Referer headers
guzzlehttp/guzzle 7.9.2 CVE-2026-67353 MODERATE 0.2% 7.15.1 Guzzle: Unbounded response cookies risk denial of service
league/commonmark 2.6.1 CVE-2026-33347 MODERATE 0.2% 2.8.2 league/commonmark has an embed extension allowed_domains bypass
guzzlehttp/guzzle 7.9.2 CVE-2026-67339 MODERATE 0.2% 7.14.2 Guzzle: Proxy-Authorization headers can be sent to origin servers
guzzlehttp/guzzle 7.9.2 CVE-2026-67355 MODERATE 0.2% 7.15.1 Guzzle: Host-only cookie scope is not preserved
guzzlehttp/psr7 2.7.0 CVE-2026-55766 MODERATE 0.2% 2.12.1 guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
league/commonmark 2.6.1 CVE-2026-30838 MODERATE 0.2% 2.8.1 CommonMark has DisallowedRawHtml extension bypass via whitespace in HTML tag names
guzzlehttp/guzzle 7.9.2 CVE-2026-69246 HIGH 0.2% 7.15.2 Guzzle: Noncanonical host can bypass host-based checks
guzzlehttp/guzzle 7.9.2 CVE-2026-55767 MODERATE 0.2% 7.12.1 guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts
league/commonmark 2.6.1 CVE-2026-71478 MODERATE 0.2% 2.9.0 league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes
guzzlehttp/psr7 2.7.0 CVE-2026-48998 MODERATE 0.2% 2.10.2 guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
guzzlehttp/psr7 2.7.0 CVE-2026-49214 MODERATE 0.2% 2.10.2 guzzlehttp/psr7 has CRLF Injection via URI Host Component
guzzlehttp/guzzle 7.9.2 CVE-2026-59883 MODERATE 0.2% 7.12.3 Guzzle: Cookie Disclosure and Injection via IP-Address Domains
guzzlehttp/guzzle 7.9.2 CVE-2026-55568 MODERATE 0.1% 7.12.1 guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext

+ 7 further findings (mostly lower severity) — available in the full export.

SBOM summary

120 direct dependencies scanned (120 pinned to exact versions) from composer.lock. Vulnerability data: OSV.dev · exploitation status: CISA KEV · exploit probability: FIRST EPSS. Findings on unpinned dependencies cover the full constraint range and may not apply to the exact version deployed.

Using ENISA's CRA Maturity Assessment Model for SMEs? This snapshot provides evidence for the Vulnerability Management domain and the product-level technical documentation question (1.3) under Governance & Documentation.

This snapshot is an automated readiness assessment, not legal advice and not a conformity assessment under the CRA.

Download SBOM (CycloneDX) Want this to watch your product continuously and draft the ENISA report the day something turns exploited? Start monitoring for €99/mo Talk to us