CRAIR CRA Readiness Snapshot

contentful/forma-36 · package-lock.json · 20 Jul 2026, 11:37 UTC
11 days until the EU Cyber Resilience Act 24-hour reporting obligation applies (11 September 2026), including for products already on the market.
2545
dependencies in scope
28
known vulnerabilities
0
actively exploited (CISA KEV)
2.5%
highest exploit probability (EPSS)

What you would have to assess for ENISA reporting tomorrow

No dependency in this snapshot currently appears in CISA's Known Exploited Vulnerabilities catalog. Today, nothing would trigger the 24-hour early-warning obligation of CRA Art. 14. That can change any day a new KEV entry lands, which is exactly what continuous monitoring is for.

All findings (28)

PackageVersionAdvisorySeverityEPSSFixed inSummary
tough-cookie dev 2.5.0 CVE-2023-26136 MODERATE 2.5% 4.1.3 tough-cookie Prototype Pollution vulnerability
robots-txt-guard dev 0.1.1 CVE-2021-4305 HIGH 0.9% 1.0.2 robots-txt-guard Inefficient Regular Expression Complexity vulnerability
undici dev 6.26.0 CVE-2026-12151 HIGH 0.8% 6.27.0 undici WebSocket client vulnerable to denial of service via fragment count bypass
undici dev 7.27.2 CVE-2026-12151 HIGH 0.8% 6.27.0 undici WebSocket client vulnerable to denial of service via fragment count bypass
decompress 4.2.1 CVE-2026-53486 CRITICAL 0.6% Decompress: Archive extraction can create files and links outside of the target directory
fast-uri 3.1.0 CVE-2026-6321 HIGH 0.5% 3.1.1 fast-uri vulnerable to path traversal via percent-encoded dot segments
useragent dev 2.3.0 CVE-2020-26311 MODERATE 0.5% useragent Regular Expression Denial of Service vulnerability
undici dev 7.27.2 CVE-2026-9697 HIGH 0.5% 7.28.0 undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
fast-uri 3.1.0 CVE-2026-6322 HIGH 0.5% 3.1.2 fast-uri vulnerable to host confusion via percent-encoded authority delimiters
basic-ftp dev 5.2.2 CVE-2026-44240 HIGH 0.5% 5.3.1 basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering
undici dev 7.27.2 CVE-2026-9678 MODERATE 0.4% 7.28.0 undici vulnerable to cross-user information disclosure via shared cache whitespace bypass
undici dev 7.27.2 CVE-2026-6734 HIGH 0.4% 7.28.0 undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse
tmp dev 0.0.33 CVE-2026-44705 HIGH 0.4% 0.2.6 tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape
uuid 8.3.2 CVE-2026-41907 MODERATE 0.3% 11.1.1 uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided
uuid dev 2.0.3 CVE-2026-41907 MODERATE 0.3% 11.1.1 uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided
basic-ftp dev 5.2.2 CVE-2026-41324 HIGH 0.3% 5.3.0 basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list()
tmp dev 0.0.33 CVE-2025-54798 LOW 0.3% 0.2.4 tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter
brace-expansion dev 5.0.5 CVE-2026-45149 MODERATE 0.3% 5.0.6 brace-expansion: Large numeric range defeats documented `max` DoS protection
js-yaml dev 3.14.2 CVE-2026-53550 MODERATE 0.3% 4.2.0 JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases
undici dev 6.26.0 CVE-2026-9679 MODERATE 0.3% 6.27.0 undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
undici dev 7.27.2 CVE-2026-9679 MODERATE 0.3% 6.27.0 undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
undici dev 6.26.0 CVE-2026-11525 LOW 0.2% 6.27.0 undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
undici dev 7.27.2 CVE-2026-11525 LOW 0.2% 6.27.0 undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
undici dev 6.26.0 CVE-2026-6733 LOW 0.2% 6.27.0 undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
undici dev 7.27.2 CVE-2026-6733 LOW 0.2% 6.27.0 undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
postcss 8.4.31 CVE-2026-41305 MODERATE 0.2% 8.5.10 PostCSS has XSS via Unescaped </style> in its CSS Stringify Output
serialize-javascript dev 4.0.0 GHSA-5c6j-r48x-rmvq HIGH 7.0.3 Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
esbuild dev 0.27.7 GHSA-g7r4-m6w7-qqqr LOW 0.28.1 esbuild allows arbitrary file read when running the development server on Windows

SBOM summary

2545 direct dependencies scanned (2545 pinned to exact versions) from package-lock.json. Vulnerability data: OSV.dev · exploitation status: CISA KEV · exploit probability: FIRST EPSS. Findings on unpinned dependencies cover the full constraint range and may not apply to the exact version deployed.

Using ENISA's CRA Maturity Assessment Model for SMEs? This snapshot provides evidence for the Vulnerability Management domain and the product-level technical documentation question (1.3) under Governance & Documentation.

This snapshot is an automated readiness assessment, not legal advice and not a conformity assessment under the CRA.

Download SBOM (CycloneDX) Want this to watch your product continuously and draft the ENISA report the day something turns exploited? Start monitoring for €99/mo Talk to us