CRA Readiness Snapshot
What you would have to assess for ENISA reporting tomorrow
No dependency in this snapshot currently appears in CISA's Known Exploited Vulnerabilities catalog. Today, nothing would trigger the 24-hour early-warning obligation of CRA Art. 14. That can change any day a new KEV entry lands, which is exactly what continuous monitoring is for.
All findings (26)
| Package | Version | Advisory | Severity | EPSS | Fixed in | Summary |
|---|---|---|---|---|---|---|
| lodash | 4.17.23 | CVE-2021-23337 | HIGH | 22.4% | 4.18.0 | lodash vulnerable to Code Injection via `_.template` imports key names |
| lodash dev | 4.17.21 | CVE-2021-23337 | HIGH | 22.4% | 4.18.0 | lodash vulnerable to Code Injection via `_.template` imports key names |
| lodash | 4.17.23 | CVE-2025-13465 | MODERATE | 1.5% | 4.18.0 | lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` |
| lodash dev | 4.17.21 | CVE-2025-13465 | MODERATE | 1.5% | 4.18.0 | lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` |
| lodash dev | 4.17.21 | CVE-2025-13465 | MODERATE | 1.5% | 4.17.23 | Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions |
| serialize-javascript dev | 6.0.2 | CVE-2026-34043 | MODERATE | 0.5% | 7.0.5 | Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects |
| ip-address dev | 10.1.0 | CVE-2026-42338 | MODERATE | 0.5% | 10.1.1 | ip-address has XSS in Address6 HTML-emitting methods |
| yaml dev | 2.7.0 | CVE-2026-33532 | MODERATE | 0.5% | 2.8.3 | yaml is vulnerable to Stack Overflow via deeply nested YAML collections |
| brace-expansion dev | 2.0.2 | CVE-2026-33750 | MODERATE | 0.4% | 5.0.5 | brace-expansion: Zero-step sequence causes process hang and memory exhaustion |
| brace-expansion dev | 1.1.12 | CVE-2026-33750 | MODERATE | 0.4% | 5.0.5 | brace-expansion: Zero-step sequence causes process hang and memory exhaustion |
| brace-expansion dev | 5.0.4 | CVE-2026-33750 | MODERATE | 0.4% | 5.0.5 | brace-expansion: Zero-step sequence causes process hang and memory exhaustion |
| picomatch dev | 4.0.3 | CVE-2026-33671 | HIGH | 0.4% | 4.0.4 | Picomatch has a ReDoS vulnerability via extglob quantifiers |
| picomatch dev | 2.3.1 | CVE-2026-33671 | HIGH | 0.4% | 4.0.4 | Picomatch has a ReDoS vulnerability via extglob quantifiers |
| picomatch dev | 4.0.2 | CVE-2026-33671 | HIGH | 0.4% | 4.0.4 | Picomatch has a ReDoS vulnerability via extglob quantifiers |
| picomatch dev | 4.0.3 | CVE-2026-33672 | MODERATE | 0.4% | 4.0.4 | Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching |
| picomatch dev | 2.3.1 | CVE-2026-33672 | MODERATE | 0.4% | 4.0.4 | Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching |
| picomatch dev | 4.0.2 | CVE-2026-33672 | MODERATE | 0.4% | 4.0.4 | Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching |
| tmp dev | 0.0.33 | CVE-2026-44705 | HIGH | 0.4% | 0.2.6 | tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape |
| tmp dev | 0.0.33 | CVE-2025-54798 | LOW | 0.3% | 0.2.4 | tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter |
| brace-expansion dev | 5.0.4 | CVE-2026-45149 | MODERATE | 0.3% | 5.0.6 | brace-expansion: Large numeric range defeats documented `max` DoS protection |
| @sigstore/core dev | 3.2.0 | CVE-2026-48758 | MODERATE | 0.3% | 3.2.1 | @sigstore/core has DSSE payloadType type-binding failure |
| sigstore dev | 4.1.0 | CVE-2026-48815 | HIGH | 0.2% | 4.1.1 | sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced |
| @sigstore/verify dev | 3.1.0 | CVE-2026-48816 | MODERATE | 0.2% | 3.1.1 | sigstore-js has Insufficient Verification of Data Authenticity |
| tar dev | 7.5.11 | CVE-2026-53655 | MODERATE | 0.1% | 7.5.16 | node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smu... |
| serialize-javascript dev | 6.0.2 | GHSA-5c6j-r48x-rmvq | HIGH | — | 7.0.3 | Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() |
| esbuild dev | 0.27.7 | GHSA-g7r4-m6w7-qqqr | LOW | — | 0.28.1 | esbuild allows arbitrary file read when running the development server on Windows |
SBOM summary
1077 direct dependencies scanned (1077 pinned to exact versions) from package-lock.json. Vulnerability data: OSV.dev · exploitation status: CISA KEV · exploit probability: FIRST EPSS. Findings on unpinned dependencies cover the full constraint range and may not apply to the exact version deployed.
Using ENISA's CRA Maturity Assessment Model for SMEs? This snapshot provides evidence for the Vulnerability Management domain and the product-level technical documentation question (1.3) under Governance & Documentation.
This snapshot is an automated readiness assessment, not legal advice and not a conformity assessment under the CRA.