Medium severity4.7OSV Advisory· Published Jul 8, 2026· Updated Jul 10, 2026
CVE-2026-59947
CVE-2026-59947
Description
Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, when Composer is run with -vvv debug verbosity, it could print a credential embedded in the username slot of a repository or package URL, such as a GitHub Personal Access Token in https://TOKEN@host/, to debug output because AuthHelper, Url::sanitize, and ProcessExecutor did not sanitize username-only URL credentials. This issue is fixed in versions 2.2.29 and 2.10.2.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
composer/composerPackagist | >= 2.3.0, < 2.10.2 | 2.10.2 |
composer/composerPackagist | >= 1.0.0, < 2.2.29 | 2.2.29 |
Affected products
5- osv-coords3 versionspkg:bitnami/composerpkg:rpm/opensuse/php-composer2&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/php-composer2&distro=openSUSE%20Tumbleweed
>= 1.0.0, < 2.2.29+ 2 more
- (no CPE)range: >= 1.0.0, < 2.2.29
- (no CPE)range: < 2.8.9-160000.4.1
- (no CPE)range: < 2.10.2-1.1
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-g6xq-892h-64w3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-59947ghsaADVISORY
- github.com/composer/composer/commit/6bd66874ae523ecb69aca5964487a0cdfda03ef8nvdWEB
- github.com/composer/composer/commit/8887ad76fbd830cb1861a2b1fd8ead78ed1fa1ecnvdWEB
- github.com/composer/composer/releases/tag/2.10.2nvdWEB
- github.com/composer/composer/releases/tag/2.2.29nvdWEB
- github.com/composer/composer/security/advisories/GHSA-g6xq-892h-64w3nvdWEB
News mentions
1- Composer: Three Vulnerabilities in Package Handling and Credential Leakage PatchedVypr Intelligence · Jul 10, 2026