CRA Readiness Snapshot
What you would have to assess for ENISA reporting tomorrow
From 11 September 2026, an actively exploited vulnerability in software you ship must be reported to ENISA within 24 hours of awareness (CRA Art. 14). In this snapshot, 1 finding is in the CISA KEV catalog (0 in production dependencies):
| Package | Your version | CVE | Fixed in | Exploit context |
|---|---|---|---|---|
| vite dev | ^6.3.0 (unpinned) | CVE-2025-31125 | 6.2.4 | KEV listed 2026-01-22 |
⚠ No lockfile — SBOM is not reproducible
This scan is based on a manifest (composer.lock, package.json), not a lockfile. 5 of 217 dependencies are version ranges, so the exact shipped versions — and their transitive dependencies — cannot be verified. Under the CRA's full obligations (11 December 2027) you must produce a machine-readable SBOM of what you actually ship. Committing a lockfile is the single highest-impact fix in this report.
All findings (66)
| Package | Version | Advisory | Severity | EPSS | Fixed in | Summary |
|---|---|---|---|---|---|---|
| vite dev | ^6.3.0 | CVE-2025-30208 | MODERATE | 75.0% | 6.2.3 | Vite bypasses server.fs.deny when using ?raw?? |
| vite dev | ^6.3.0 | CVE-2025-31486 | MODERATE | 40.5% | 6.2.5 | Vite allows server.fs.deny to be bypassed with .svg or relative paths |
| axios dev | ^1.6.4 | CVE-2021-3749 | HIGH | 8.5% | 0.21.2 | axios Inefficient Regular Expression Complexity vulnerability |
| axios dev | ^1.6.4 | CVE-2019-10742 | HIGH | 6.0% | 0.18.1 | Denial of Service in axios |
| vite dev | ^6.3.0 | CVE-2026-39363 | HIGH | 3.4% | 8.0.5 | Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket |
| vite dev | ^6.3.0 | CVE-2023-34092 | HIGH | 3.1% | 2.9.16 | Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//) |
| axios dev | ^1.6.4 | CVE-2026-25639 | HIGH | 2.8% | 1.13.5 | Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig |
| axios dev | ^1.6.4 | CVE-2020-28168 | MODERATE | 2.4% | 0.21.1 | Axios vulnerable to Server-Side Request Forgery |
| vite dev | ^6.3.0 | CVE-2026-39364 | HIGH | 2.1% | 8.0.5 | Vite: `server.fs.deny` bypassed with queries |
| axios dev | ^1.6.4 | CVE-2026-40175 | MODERATE | 1.9% | 1.15.0 | Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain |
| vite dev | ^6.3.0 | CVE-2025-32395 | MODERATE | 1.7% | 6.2.6 | Vite has an `server.fs.deny` bypass with an invalid `request-target` |
| vite dev | ^6.3.0 | CVE-2022-35204 | HIGH | 1.3% | 2.9.13 | Vite before v2.9.13 vulnerable to directory traversal via crafted URL to victim's service |
| vite dev | ^6.3.0 | CVE-2025-58751 | LOW | 1.2% | 7.1.5 | Vite middleware may serve files starting with the same name with the public directory |
| axios dev | ^1.6.4 | CVE-2024-39338 | HIGH | 1.2% | 1.7.4 | Server-Side Request Forgery in axios |
| axios dev | ^1.6.4 | CVE-2025-62718 | MODERATE | 1.2% | 1.15.0 | Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF |
| vite dev | ^6.3.0 | CVE-2025-46565 | MODERATE | 1.2% | 6.3.4 | Vite's server.fs.deny bypassed with /. for files under project root |
| axios dev | ^1.6.4 | CVE-2025-58754 | HIGH | 1.1% | 1.12.0 | Axios is vulnerable to DoS attack through lack of data size check |
| vite dev | ^6.3.0 | CVE-2024-45811 | MODERATE | 1.1% | 5.4.6 | Vite's `server.fs.deny` is bypassed when using `?import&raw` |
| axios dev | ^1.6.4 | CVE-2026-44494 | HIGH | 1.0% | 1.16.0 | axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy` |
| vite dev | ^6.3.0 | CVE-2025-62522 | MODERATE | 1.0% | 7.1.11 | vite allows server.fs.deny bypass via backslash on Windows |
| vite dev | ^6.3.0 | CVE-2023-49293 | MODERATE | 1.0% | 4.4.12 | Vite XSS vulnerability in `server.transformIndexHtml` via URL payload |
| vite dev | ^6.3.0 | CVE-2026-39365 | MODERATE | 0.9% | 8.0.5 | Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling |
| axios dev | ^1.6.4 | CVE-2026-44492 | HIGH | 0.9% | 1.16.0 | axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718) |
| axios dev | ^1.6.4 | CVE-2026-42033 | HIGH | 0.8% | 1.15.1 | Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking |
| axios dev | ^1.6.4 | CVE-2026-44495 | HIGH | 0.8% | 1.15.2 | axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge |
| vite dev | ^6.3.0 | CVE-2024-23331 | HIGH | 0.8% | 2.9.17 | Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem |
| axios dev | ^1.6.4 | CVE-2025-27152 | HIGH | 0.8% | 1.8.2 | axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL |
| axios dev | ^1.6.4 | CVE-2026-42039 | MODERATE | 0.7% | 1.15.1 | Axios: unbounded recursion in toFormData causes DoS via deeply nested request data |
| axios dev | ^1.6.4 | CVE-2026-39865 | MODERATE | 0.7% | 1.13.2 | Axios HTTP/2 Session Cleanup State Corruption Vulnerability |
| axios dev | ^1.6.4 | CVE-2026-42264 | HIGH | 0.7% | 1.15.2 | Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking |
+ 36 further findings (mostly lower severity) — available in the full export.
SBOM summary
217 direct dependencies scanned (212 pinned to exact versions) from composer.lock, package.json. Vulnerability data: OSV.dev · exploitation status: CISA KEV · exploit probability: FIRST EPSS. Findings on unpinned dependencies cover the full constraint range and may not apply to the exact version deployed.
Using ENISA's CRA Maturity Assessment Model for SMEs? This snapshot provides evidence for the Vulnerability Management domain and the product-level technical documentation question (1.3) under Governance & Documentation.
This snapshot is an automated readiness assessment, not legal advice and not a conformity assessment under the CRA.