CRAIR CRA Readiness Snapshot

contentful/contentful.js · package-lock.json · 20 Jul 2026, 11:30 UTC
11 days until the EU Cyber Resilience Act 24-hour reporting obligation applies (11 September 2026), including for products already on the market.
1077
dependencies in scope
26
known vulnerabilities
0
actively exploited (CISA KEV)
22.4%
highest exploit probability (EPSS)

What you would have to assess for ENISA reporting tomorrow

No dependency in this snapshot currently appears in CISA's Known Exploited Vulnerabilities catalog. Today, nothing would trigger the 24-hour early-warning obligation of CRA Art. 14. That can change any day a new KEV entry lands, which is exactly what continuous monitoring is for.

All findings (26)

PackageVersionAdvisorySeverityEPSSFixed inSummary
lodash 4.17.23 CVE-2021-23337 HIGH 22.4% 4.18.0 lodash vulnerable to Code Injection via `_.template` imports key names
lodash dev 4.17.21 CVE-2021-23337 HIGH 22.4% 4.18.0 lodash vulnerable to Code Injection via `_.template` imports key names
lodash 4.17.23 CVE-2025-13465 MODERATE 1.5% 4.18.0 lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`
lodash dev 4.17.21 CVE-2025-13465 MODERATE 1.5% 4.18.0 lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`
lodash dev 4.17.21 CVE-2025-13465 MODERATE 1.5% 4.17.23 Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions
serialize-javascript dev 6.0.2 CVE-2026-34043 MODERATE 0.5% 7.0.5 Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects
ip-address dev 10.1.0 CVE-2026-42338 MODERATE 0.5% 10.1.1 ip-address has XSS in Address6 HTML-emitting methods
yaml dev 2.7.0 CVE-2026-33532 MODERATE 0.5% 2.8.3 yaml is vulnerable to Stack Overflow via deeply nested YAML collections
brace-expansion dev 2.0.2 CVE-2026-33750 MODERATE 0.4% 5.0.5 brace-expansion: Zero-step sequence causes process hang and memory exhaustion
brace-expansion dev 1.1.12 CVE-2026-33750 MODERATE 0.4% 5.0.5 brace-expansion: Zero-step sequence causes process hang and memory exhaustion
brace-expansion dev 5.0.4 CVE-2026-33750 MODERATE 0.4% 5.0.5 brace-expansion: Zero-step sequence causes process hang and memory exhaustion
picomatch dev 4.0.3 CVE-2026-33671 HIGH 0.4% 4.0.4 Picomatch has a ReDoS vulnerability via extglob quantifiers
picomatch dev 2.3.1 CVE-2026-33671 HIGH 0.4% 4.0.4 Picomatch has a ReDoS vulnerability via extglob quantifiers
picomatch dev 4.0.2 CVE-2026-33671 HIGH 0.4% 4.0.4 Picomatch has a ReDoS vulnerability via extglob quantifiers
picomatch dev 4.0.3 CVE-2026-33672 MODERATE 0.4% 4.0.4 Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching
picomatch dev 2.3.1 CVE-2026-33672 MODERATE 0.4% 4.0.4 Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching
picomatch dev 4.0.2 CVE-2026-33672 MODERATE 0.4% 4.0.4 Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching
tmp dev 0.0.33 CVE-2026-44705 HIGH 0.4% 0.2.6 tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape
tmp dev 0.0.33 CVE-2025-54798 LOW 0.3% 0.2.4 tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter
brace-expansion dev 5.0.4 CVE-2026-45149 MODERATE 0.3% 5.0.6 brace-expansion: Large numeric range defeats documented `max` DoS protection
@sigstore/core dev 3.2.0 CVE-2026-48758 MODERATE 0.3% 3.2.1 @sigstore/core has DSSE payloadType type-binding failure
sigstore dev 4.1.0 CVE-2026-48815 HIGH 0.2% 4.1.1 sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced
@sigstore/verify dev 3.1.0 CVE-2026-48816 MODERATE 0.2% 3.1.1 sigstore-js has Insufficient Verification of Data Authenticity
tar dev 7.5.11 CVE-2026-53655 MODERATE 0.1% 7.5.16 node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smu...
serialize-javascript dev 6.0.2 GHSA-5c6j-r48x-rmvq HIGH 7.0.3 Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
esbuild dev 0.27.7 GHSA-g7r4-m6w7-qqqr LOW 0.28.1 esbuild allows arbitrary file read when running the development server on Windows

SBOM summary

1077 direct dependencies scanned (1077 pinned to exact versions) from package-lock.json. Vulnerability data: OSV.dev · exploitation status: CISA KEV · exploit probability: FIRST EPSS. Findings on unpinned dependencies cover the full constraint range and may not apply to the exact version deployed.

Using ENISA's CRA Maturity Assessment Model for SMEs? This snapshot provides evidence for the Vulnerability Management domain and the product-level technical documentation question (1.3) under Governance & Documentation.

This snapshot is an automated readiness assessment, not legal advice and not a conformity assessment under the CRA.

Download SBOM (CycloneDX) Want this to watch your product continuously and draft the ENISA report the day something turns exploited? Start monitoring for €99/mo Talk to us