CRA Readiness Snapshot
What you would have to assess for ENISA reporting tomorrow
No dependency in this snapshot currently appears in CISA's Known Exploited Vulnerabilities catalog. Today, nothing would trigger the 24-hour early-warning obligation of CRA Art. 14. That can change any day a new KEV entry lands, which is exactly what continuous monitoring is for.
All findings (28)
| Package | Version | Advisory | Severity | EPSS | Fixed in | Summary |
|---|---|---|---|---|---|---|
| tough-cookie dev | 2.5.0 | CVE-2023-26136 | MODERATE | 2.5% | 4.1.3 | tough-cookie Prototype Pollution vulnerability |
| robots-txt-guard dev | 0.1.1 | CVE-2021-4305 | HIGH | 0.9% | 1.0.2 | robots-txt-guard Inefficient Regular Expression Complexity vulnerability |
| undici dev | 6.26.0 | CVE-2026-12151 | HIGH | 0.8% | 6.27.0 | undici WebSocket client vulnerable to denial of service via fragment count bypass |
| undici dev | 7.27.2 | CVE-2026-12151 | HIGH | 0.8% | 6.27.0 | undici WebSocket client vulnerable to denial of service via fragment count bypass |
| decompress | 4.2.1 | CVE-2026-53486 | CRITICAL | 0.6% | — | Decompress: Archive extraction can create files and links outside of the target directory |
| fast-uri | 3.1.0 | CVE-2026-6321 | HIGH | 0.5% | 3.1.1 | fast-uri vulnerable to path traversal via percent-encoded dot segments |
| useragent dev | 2.3.0 | CVE-2020-26311 | MODERATE | 0.5% | — | useragent Regular Expression Denial of Service vulnerability |
| undici dev | 7.27.2 | CVE-2026-9697 | HIGH | 0.5% | 7.28.0 | undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent |
| fast-uri | 3.1.0 | CVE-2026-6322 | HIGH | 0.5% | 3.1.2 | fast-uri vulnerable to host confusion via percent-encoded authority delimiters |
| basic-ftp dev | 5.2.2 | CVE-2026-44240 | HIGH | 0.5% | 5.3.1 | basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering |
| undici dev | 7.27.2 | CVE-2026-9678 | MODERATE | 0.4% | 7.28.0 | undici vulnerable to cross-user information disclosure via shared cache whitespace bypass |
| undici dev | 7.27.2 | CVE-2026-6734 | HIGH | 0.4% | 7.28.0 | undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse |
| tmp dev | 0.0.33 | CVE-2026-44705 | HIGH | 0.4% | 0.2.6 | tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape |
| uuid | 8.3.2 | CVE-2026-41907 | MODERATE | 0.3% | 11.1.1 | uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided |
| uuid dev | 2.0.3 | CVE-2026-41907 | MODERATE | 0.3% | 11.1.1 | uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided |
| basic-ftp dev | 5.2.2 | CVE-2026-41324 | HIGH | 0.3% | 5.3.0 | basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list() |
| tmp dev | 0.0.33 | CVE-2025-54798 | LOW | 0.3% | 0.2.4 | tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter |
| brace-expansion dev | 5.0.5 | CVE-2026-45149 | MODERATE | 0.3% | 5.0.6 | brace-expansion: Large numeric range defeats documented `max` DoS protection |
| js-yaml dev | 3.14.2 | CVE-2026-53550 | MODERATE | 0.3% | 4.2.0 | JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases |
| undici dev | 6.26.0 | CVE-2026-9679 | MODERATE | 0.3% | 6.27.0 | undici vulnerable to HTTP header injection via Set-Cookie percent-decoding |
| undici dev | 7.27.2 | CVE-2026-9679 | MODERATE | 0.3% | 6.27.0 | undici vulnerable to HTTP header injection via Set-Cookie percent-decoding |
| undici dev | 6.26.0 | CVE-2026-11525 | LOW | 0.2% | 6.27.0 | undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching |
| undici dev | 7.27.2 | CVE-2026-11525 | LOW | 0.2% | 6.27.0 | undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching |
| undici dev | 6.26.0 | CVE-2026-6733 | LOW | 0.2% | 6.27.0 | undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse |
| undici dev | 7.27.2 | CVE-2026-6733 | LOW | 0.2% | 6.27.0 | undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse |
| postcss | 8.4.31 | CVE-2026-41305 | MODERATE | 0.2% | 8.5.10 | PostCSS has XSS via Unescaped </style> in its CSS Stringify Output |
| serialize-javascript dev | 4.0.0 | GHSA-5c6j-r48x-rmvq | HIGH | — | 7.0.3 | Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() |
| esbuild dev | 0.27.7 | GHSA-g7r4-m6w7-qqqr | LOW | — | 0.28.1 | esbuild allows arbitrary file read when running the development server on Windows |
SBOM summary
2545 direct dependencies scanned (2545 pinned to exact versions) from package-lock.json. Vulnerability data: OSV.dev · exploitation status: CISA KEV · exploit probability: FIRST EPSS. Findings on unpinned dependencies cover the full constraint range and may not apply to the exact version deployed.
Using ENISA's CRA Maturity Assessment Model for SMEs? This snapshot provides evidence for the Vulnerability Management domain and the product-level technical documentation question (1.3) under Governance & Documentation.
This snapshot is an automated readiness assessment, not legal advice and not a conformity assessment under the CRA.