Sample report

A real report, run on an example SBOM.

The input is an example SBOM from our own test suite, written for a fictional product: acme-desktop 3.4.0, 5 components. The vulnerability data is a snapshot of OSV.dev, the CISA catalogue of known exploited vulnerabilities and FIRST EPSS, taken on 2026-10-08. The findings and the regulation checklist below are the same kind of answer your account gives for your own SBOM.

CRA exposure report

acme-desktop 3.4.0

Sample report, a standalone document. In the app, your product page shows the same kind of answer: findings with fixes, and the regulation checklist.

Work to schedule5 components · 4 checked · 14 findings · 1 not checked
0
Known exploited
0
Critical
3
High
7
Medium and below
4
Not rated

1 component(s) carry no package URL and could not be checked (20% of the SBOM). They are counted here so the number you see is the real coverage, not a rounded-up one.

Start here

Three things, in order. Everything else can wait a week.

  1. Upgrade lodash to 4.17.21 or later. It clears CVE-2021-23337 without any code change on your side.
  2. Set the alert contact and run the reporting workflow once end to end on a test case. The first time you do this must not be during a real incident.
  3. Record it. The reporting obligation covers products already on the market, so this date decides whether the obligation applies to you from day one.

Findings

Ordered by known exploitation, then severity, then probability of exploitation.

ComponentVulnerabilitySeverityExploitedFix
lodash
4.17.20
CVE-2021-23337
lodash vulnerable to Code Injection via `_.template` imports key names
High 8.1This week
EPSS 21%
4.17.21
@angular/core
12.0.1
CVE-2026-22610
Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
HighPlan a fix
EPSS 0.44%
19.2.18
@angular/core
12.0.1
CVE-2026-69151
Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes
HighPlan a fix
EPSS 0.33%
20.3.27
debian/openssl
1.1.1n-0+deb11u5
CVE-2023-5678
openssl - security update
Not ratedReview this week
EPSS 52% (CVE-2024-2511)
1.1.1n-0+deb11u6 · 1.1.1w-0+deb11u2
debian/openssl
1.1.1n-0+deb11u5
CVE-2025-9230
openssl - security update
Not ratedReview this week
EPSS 1.6%
1.1.1w-0+deb11u4
lodash
4.17.20
CVE-2020-28500
Regular Expression Denial of Service (ReDoS) in lodash
Medium 5.3Plan a fix
EPSS 7.3%
4.17.21
lodash
4.17.20
CVE-2025-13465
lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`
Medium 6.5Plan a fix
EPSS 1.8%
4.17.23
@angular/core
12.0.1
CVE-2026-27970
Angular i18n vulnerable to Cross-Site Scripting
Medium 6.1Monitor
EPSS 0.46%
19.2.19
@angular/core
12.0.1
CVE-2026-52725
@angular/core: Angular Template and Dynamic Component Namespace Bypass leading to Cross-Site Scripting (XSS)
Medium 6.1Monitor
EPSS 0.40%
19.2.23
@angular/core
12.0.1
CVE-2026-88057
Angular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compiler
MediumMonitor
EPSS 0.37%
20.3.28
@angular/core
12.0.1
CVE-2026-50557
Angular: Template and Attribute Namespace Sanitization Bypass (XSS)
Medium 6.1Monitor
EPSS 0.34%
19.2.22
@angular/core
12.0.1
CVE-2026-54267
Angular Client Hydration DOM Clobbering & Response-Cache Poisoning
Medium 6.1Monitor
EPSS 0.32%
20.3.25
debian/openssl
1.1.1n-0+deb11u5
CVE-2025-68160
openssl - security update
Not ratedRate it yourself
EPSS 0.96% (CVE-2025-69421)
1.1.1w-0+deb11u5
debian/openssl
1.1.1n-0+deb11u5
CVE-2024-13176
openssl - security update
Not ratedRate it yourself
EPSS 0.61%
1.1.1w-0+deb11u3
This week.
High or critical severity with a measurable chance of exploitation. Fix this week.
Plan a fix.
High or critical severity with no current signal of exploitation, or lower severity with a measurable chance of exploitation. Put it in the plan.
Review this week.
The source gives no severity rating, but the chance of exploitation is measurable. Read the advisory and rate it yourself this week.
Monitor.
Medium or lower severity with no measurable chance of exploitation. Fix it with your regular updates. It stays on the list until it is fixed or ruled not affected.
Rate it yourself.
The source gives no severity rating and nothing points to exploitation. Read the advisory and rate it yourself. It stays on the list until it is fixed or ruled not affected.

Not checked

1 of 5 components

A component that is missing from Findings is not necessarily clean. These components were not fully matched against advisories. The reason is given for each group.

Not checked: The SBOM gives no package URL for this component, so it cannot be matched to advisories.

1 component: vendored-libfoo.so

Regulation checklist

2 of 9 in place · nearest deadline 2026-09-11

In placeProduct falls within the scope of the Regulationby 2026-09-11

You classified this product as a product with digital elements placed on the EU market.

Not assessedDate the product was placed on the EU market is recordedby 2026-09-11

The date this product was placed on the EU market has not been recorded.

→ Record it. The reporting obligation covers products already on the market, so this date decides whether the obligation applies to you from day one.

MissingReady to report an actively exploited vulnerability within 24 hoursby 2026-09-11

No contact is set to receive the alert about an exploited vulnerability. The 24-hour clock starts when you open a case, not when the alert arrives.

→ Set the alert contact and run the reporting workflow once end to end on a test case. The first time you do this must not be during a real incident.

MissingCoordinated vulnerability disclosure policy is publishedby 2027-12-11

No coordinated vulnerability disclosure policy was found.

→ Publish a CVD policy that states where to report, what you promise in return and on what timeline.

Missingsecurity.txt exposes a reporting contactby 2027-12-11

No security.txt was found at /.well-known/security.txt.

→ Publish /.well-known/security.txt with a contact address and an expiry date. It is the first place a finder looks.

In placeSoftware bill of materials in a machine-readable formatby 2027-12-11

An SBOM is present and 80% of its components are identified and monitored.

MissingVulnerability handling and update policy is documentedby 2027-12-11

No documented process for handling vulnerabilities and shipping updates was found.

→ Document how a report reaches you, who triages it, how fast a fix ships and how users are told. One page is enough; nothing is not.

MissingDeclared support period with security updatesby 2027-12-11

No support period has been declared for this product.

→ Declare the date until which you will ship security updates, and publish it where buyers see it before purchase.

MissingTechnical documentation (Annex VII) existsby 2027-12-11

No technical documentation was found for this product.

→ Start the Annex VII skeleton now and fill it as the product changes. Assembling it from scratch in late 2027 is the expensive way.

About this data

  • 1 component(s) carry no usable package URL and are not checked for known vulnerabilities.

Sources

Every statement about the Regulation below leads to where it comes from.

Manufacturers, importers and distributors of products with digital elements sold in the EU, including companies established outside the EU.

https://eur-lex.europa.eu/eli/reg/2024/2847/oj

From 2026-09-11, manufacturers must report actively exploited vulnerabilities and severe incidents through the ENISA single reporting platform: early warning within 24 hours, a detailed notification within 72 hours, and a final report within 14 days for a vulnerability or one month for an incident. This applies to products already placed on the market.

https://www.crowell.com/en/insights/client-alerts/eu-cyber-resilience-act-countdown-11-september-2026-incidentvulnerability-reporting-deadline-is-less-than-100-days-away

Manufacturers must have a coordinated vulnerability disclosure policy and a contact address for reporting vulnerabilities.

https://eur-lex.europa.eu/eli/reg/2024/2847/oj

Manufacturers must identify and document vulnerabilities and components contained in their products, including by drawing up a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies of the products.

Not independently verified. Confirm before relying on it. https://eur-lex.europa.eu/eli/reg/2024/2847/oj

Manufacturers must handle vulnerabilities without delay and provide security updates for the declared support period of the product.

https://eur-lex.europa.eu/eli/reg/2024/2847/oj

Manufacturers must draw up technical documentation (Annex VII) and an EU declaration of conformity before placing the product on the market.

https://eur-lex.europa.eu/eli/reg/2024/2847/oj

Vulnerability data: OSV.dev, CISA Known Exploited Vulnerabilities catalog, FIRST EPSS. Generated 2026-10-08T12:44:32.855Z by Musterproof.

This material is generated from your own product data and public sources. It is not legal advice. Have a qualified adviser review your compliance documentation before you rely on it.

None of these findings is in the CISA catalogue of known exploited vulnerabilities, so nothing is flagged as needing action today. When a component is, it moves to the top of the list and the first step becomes assessing, that day, whether the 24-hour reporting obligation applies to you.

Get one for your product

Post your own SBOM and your account shows the same kind of answer: what is exploitable, what to upgrade to, and what the Regulation expects you to have by each date. We never see your source code.

Questions: support@musterproof.com