SBOM Exposure Snapshot
Upload or paste a CycloneDX, SPDX JSON document or dependency manifest to scan all declared components against the OSV.dev open vulnerability database. The scanner identifies known CVEs and security advisories with precise version matching, returning an immediate severity breakdown across Critical, High, Medium, and Low vulnerabilities alongside top exposed components. The live interactive scanner is available at /sbom-exposure with no registration required. The tool operates in-request and does not store your SBOM data on our servers. For continuous vulnerability monitoring and full CRA Annex I Part II(1) due diligence, CVD Portal integrates SBOM ingestion with automated alerting and CSAF 2.0 advisory generation.
Last updated 29 August 2026
Key takeaways
- Annex I Part II(1) mandates that manufacturers identify and document component vulnerabilities throughout the entire product lifecycle.
- Article 13(5) obligates manufacturers to exercise and document due diligence when integrating third-party software components.
- Vulnerability exposure analysis matches declared component versions against open advisory feeds aggregated in the OSV.dev database.
- Supported SBOM and manifest formats include CycloneDX JSON, SPDX 2.3, SPDX 3.0, and standard ecosystem dependency files.
Accepts CycloneDX or SPDX JSON, or a dependency manifest (package.json, requirements.txt, go.mod, Cargo.toml, Gemfile.lock).
Analysed in-request. Your SBOM is never stored on our servers.

Frequently asked
Where can I run the SBOM exposure snapshot tool?+
The live tool is available at /sbom-exposure. You can upload a CycloneDX or SPDX JSON document, or a package dependency manifest, to run an immediate vulnerability exposure scan.
What formats does the SBOM exposure snapshot support?+
The tool accepts CycloneDX JSON, SPDX 2.3 and 3.0 JSON, as well as package dependency manifests including package.json, requirements.txt, go.mod, Cargo.toml, and Gemfile.lock.
How are vulnerabilities matched against components?+
Components and their exact version strings are matched against OSV.dev, an open vulnerability database aggregating GitHub Security Advisories, RustSec, PyPA, Go vulnerability database, and distribution security feeds.
Does this tool upload or store my SBOM?+
No. The document is analysed in-request and is never stored on our servers or in any database. The scan results are returned directly to your browser.
How does SBOM exposure scanning help with CRA compliance?+
CRA Annex I Part II(1) requires manufacturers to identify and document vulnerabilities in components throughout the product lifecycle. Article 13(5) obligates manufacturers to exercise due diligence on third-party components. Regular SBOM vulnerability scanning provides the evidence needed to demonstrate component due diligence.
Other free CRA tools
Ready to automate your CVD programme?
CVD Portal integrates all these tools and handles your Article 13 and 14 obligations automatically.
Start your free portal →