VYPR
High severity7.5NVD Advisory· Published Jul 15, 2026· Updated Jul 15, 2026

CVE-2026-45793

CVE-2026-45793

Description

Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\IO\BaseIO::loadConfiguration() validates GitHub OAuth tokens with the regex ^[.A-Za-z0-9_]+$ and interpolates rejected tokens into an UnexpectedValueException; GitHub Actions GITHUB_TOKEN values using the ghs__ format can contain -, fail validation, and be disclosed to stderr or CI logs. This issue is fixed in versions 1.10.28, 2.2.28, and 2.9.8.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
composer/composerPackagist
>= 2.3.0, < 2.9.82.9.8
composer/composerPackagist
>= 2.0.0, < 2.2.282.2.28
composer/composerPackagist
>= 1.0, < 1.10.281.10.28

Affected products

4

Patches

Vulnerability mechanics

References

12

News mentions

1