Sample report
A real report, run on an example SBOM.
The input is an example SBOM from our own test suite, written for a fictional product: acme-desktop 3.4.0, 5 components. The vulnerability data is a snapshot of OSV.dev, the CISA catalogue of known exploited vulnerabilities and FIRST EPSS, taken on 2026-10-08. The findings and the regulation checklist below are the same kind of answer your account gives for your own SBOM.
CRA exposure report
acme-desktop 3.4.0
Sample report, a standalone document. In the app, your product page shows the same kind of answer: findings with fixes, and the regulation checklist.
1 component(s) carry no package URL and could not be checked (20% of the SBOM). They are counted here so the number you see is the real coverage, not a rounded-up one.
Start here
Three things, in order. Everything else can wait a week.
- Upgrade lodash to 4.17.21 or later. It clears CVE-2021-23337 without any code change on your side.
- Set the alert contact and run the reporting workflow once end to end on a test case. The first time you do this must not be during a real incident.
- Record it. The reporting obligation covers products already on the market, so this date decides whether the obligation applies to you from day one.
Findings
Ordered by known exploitation, then severity, then probability of exploitation.
| Component | Vulnerability | Severity | Exploited | Fix |
|---|---|---|---|---|
lodash 4.17.20 | CVE-2021-23337 lodash vulnerable to Code Injection via `_.template` imports key names | High 8.1 | This week EPSS 21% | 4.17.21 |
@angular/core 12.0.1 | CVE-2026-22610 Angular has XSS Vulnerability via Unsanitized SVG Script Attributes | High | Plan a fix EPSS 0.44% | 19.2.18 |
@angular/core 12.0.1 | CVE-2026-69151 Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes | High | Plan a fix EPSS 0.33% | 20.3.27 |
debian/openssl 1.1.1n-0+deb11u5 | CVE-2023-5678 openssl - security update | Not rated | Review this week EPSS 52% (CVE-2024-2511) | 1.1.1n-0+deb11u6 · 1.1.1w-0+deb11u2 |
debian/openssl 1.1.1n-0+deb11u5 | CVE-2025-9230 openssl - security update | Not rated | Review this week EPSS 1.6% | 1.1.1w-0+deb11u4 |
lodash 4.17.20 | CVE-2020-28500 Regular Expression Denial of Service (ReDoS) in lodash | Medium 5.3 | Plan a fix EPSS 7.3% | 4.17.21 |
lodash 4.17.20 | CVE-2025-13465 lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` | Medium 6.5 | Plan a fix EPSS 1.8% | 4.17.23 |
@angular/core 12.0.1 | CVE-2026-27970 Angular i18n vulnerable to Cross-Site Scripting | Medium 6.1 | Monitor EPSS 0.46% | 19.2.19 |
@angular/core 12.0.1 | CVE-2026-52725 @angular/core: Angular Template and Dynamic Component Namespace Bypass leading to Cross-Site Scripting (XSS) | Medium 6.1 | Monitor EPSS 0.40% | 19.2.23 |
@angular/core 12.0.1 | CVE-2026-88057 Angular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compiler | Medium | Monitor EPSS 0.37% | 20.3.28 |
@angular/core 12.0.1 | CVE-2026-50557 Angular: Template and Attribute Namespace Sanitization Bypass (XSS) | Medium 6.1 | Monitor EPSS 0.34% | 19.2.22 |
@angular/core 12.0.1 | CVE-2026-54267 Angular Client Hydration DOM Clobbering & Response-Cache Poisoning | Medium 6.1 | Monitor EPSS 0.32% | 20.3.25 |
debian/openssl 1.1.1n-0+deb11u5 | CVE-2025-68160 openssl - security update | Not rated | Rate it yourself EPSS 0.96% (CVE-2025-69421) | 1.1.1w-0+deb11u5 |
debian/openssl 1.1.1n-0+deb11u5 | CVE-2024-13176 openssl - security update | Not rated | Rate it yourself EPSS 0.61% | 1.1.1w-0+deb11u3 |
- This week.
- High or critical severity with a measurable chance of exploitation. Fix this week.
- Plan a fix.
- High or critical severity with no current signal of exploitation, or lower severity with a measurable chance of exploitation. Put it in the plan.
- Review this week.
- The source gives no severity rating, but the chance of exploitation is measurable. Read the advisory and rate it yourself this week.
- Monitor.
- Medium or lower severity with no measurable chance of exploitation. Fix it with your regular updates. It stays on the list until it is fixed or ruled not affected.
- Rate it yourself.
- The source gives no severity rating and nothing points to exploitation. Read the advisory and rate it yourself. It stays on the list until it is fixed or ruled not affected.
Not checked
1 of 5 components
A component that is missing from Findings is not necessarily clean. These components were not fully matched against advisories. The reason is given for each group.
Not checked: The SBOM gives no package URL for this component, so it cannot be matched to advisories.
1 component: vendored-libfoo.so
Regulation checklist
2 of 9 in place · nearest deadline 2026-09-11
You classified this product as a product with digital elements placed on the EU market.
The date this product was placed on the EU market has not been recorded.
→ Record it. The reporting obligation covers products already on the market, so this date decides whether the obligation applies to you from day one.
No contact is set to receive the alert about an exploited vulnerability. The 24-hour clock starts when you open a case, not when the alert arrives.
→ Set the alert contact and run the reporting workflow once end to end on a test case. The first time you do this must not be during a real incident.
No coordinated vulnerability disclosure policy was found.
→ Publish a CVD policy that states where to report, what you promise in return and on what timeline.
No security.txt was found at /.well-known/security.txt.
→ Publish /.well-known/security.txt with a contact address and an expiry date. It is the first place a finder looks.
An SBOM is present and 80% of its components are identified and monitored.
No documented process for handling vulnerabilities and shipping updates was found.
→ Document how a report reaches you, who triages it, how fast a fix ships and how users are told. One page is enough; nothing is not.
No support period has been declared for this product.
→ Declare the date until which you will ship security updates, and publish it where buyers see it before purchase.
No technical documentation was found for this product.
→ Start the Annex VII skeleton now and fill it as the product changes. Assembling it from scratch in late 2027 is the expensive way.
About this data
- 1 component(s) carry no usable package URL and are not checked for known vulnerabilities.
Sources
Every statement about the Regulation below leads to where it comes from.
Manufacturers, importers and distributors of products with digital elements sold in the EU, including companies established outside the EU.
https://eur-lex.europa.eu/eli/reg/2024/2847/oj
From 2026-09-11, manufacturers must report actively exploited vulnerabilities and severe incidents through the ENISA single reporting platform: early warning within 24 hours, a detailed notification within 72 hours, and a final report within 14 days for a vulnerability or one month for an incident. This applies to products already placed on the market.
https://www.crowell.com/en/insights/client-alerts/eu-cyber-resilience-act-countdown-11-september-2026-incidentvulnerability-reporting-deadline-is-less-than-100-days-away
Manufacturers must have a coordinated vulnerability disclosure policy and a contact address for reporting vulnerabilities.
https://eur-lex.europa.eu/eli/reg/2024/2847/oj
Manufacturers must identify and document vulnerabilities and components contained in their products, including by drawing up a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies of the products.
Not independently verified. Confirm before relying on it. https://eur-lex.europa.eu/eli/reg/2024/2847/oj
Manufacturers must handle vulnerabilities without delay and provide security updates for the declared support period of the product.
https://eur-lex.europa.eu/eli/reg/2024/2847/oj
Manufacturers must draw up technical documentation (Annex VII) and an EU declaration of conformity before placing the product on the market.
https://eur-lex.europa.eu/eli/reg/2024/2847/oj
Vulnerability data: OSV.dev, CISA Known Exploited Vulnerabilities catalog, FIRST EPSS. Generated 2026-10-08T12:44:32.855Z by Musterproof.
This material is generated from your own product data and public sources. It is not legal advice. Have a qualified adviser review your compliance documentation before you rely on it.
None of these findings is in the CISA catalogue of known exploited vulnerabilities, so nothing is flagged as needing action today. When a component is, it moves to the top of the list and the first step becomes assessing, that day, whether the 24-hour reporting obligation applies to you.
Get one for your product
Post your own SBOM and your account shows the same kind of answer: what is exploitable, what to upgrade to, and what the Regulation expects you to have by each date. We never see your source code.
Questions: support@musterproof.com