rpm package
opensuse/php-composer2&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/php-composer2&distro=openSUSE%20Leap%2016.0
Vulnerabilities (7)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-45793 | Hig | 7.5 | < 2.8.9-160000.4.1 | 2.8.9-160000.4.1 | Jul 15, 2026 | Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\IO\BaseIO::loadConfiguration() validates GitHub OAuth tokens with the regex ^[.A-Za-z0-9_]+$ and interpolates rejected tokens into an UnexpectedValueException; GitHub Actions GITH | |
| CVE-2026-59948 | Hig | 7.0 | < 2.8.9-160000.4.1 | 2.8.9-160000.4.1 | Jul 8, 2026 | Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an untrusted repository other than Packagist.org or Private Packagist can cause Composer to write attacker-controlled files outside the vendor directory and outsi | |
| CVE-2026-59947 | Med | 4.7 | < 2.8.9-160000.4.1 | 2.8.9-160000.4.1 | Jul 8, 2026 | Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, when Composer is run with -vvv debug verbosity, it could print a credential embedded in the username slot of a repository or package URL, such as a GitHub Personal Access Token in https://TOKEN@hos | |
| CVE-2026-59946 | Med | 6.1 | < 2.8.9-160000.4.1 | 2.8.9-160000.4.1 | Jul 8, 2026 | Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containing .. path segments can resolve outside the package install directory and cause Composer's binary installation flow to chmod an existing host file to a world-re | |
| CVE-2026-40261 | Hig | 8.8 | < 2.8.9-160000.4.1 | 2.8.9-160000.4.1 | Apr 15, 2026 | Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $sourceReference parameter to a shell command without proper escaping, and additionally | |
| CVE-2026-40176 | Hig | 7.8 | < 2.8.9-160000.4.1 | 2.8.9-160000.4.1 | Apr 15, 2026 | Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::generateP4Command() method, which constructs shell commands by interpolating user-supplied Perforce connection parameters (port, | |
| CVE-2025-67746 | Med | 4.3 | < 2.8.9-160000.4.1 | 2.8.9-160000.4.1 | Dec 30, 2025 | Composer is a dependency manager for PHP. In versions on the 2.x branch prior to 2.2.26 and 2.9.3, attackers controlling remote sources that Composer downloads from might in some way inject ANSI control characters in the terminal output of various Composer commands, causing mangl |
- affected < 2.8.9-160000.4.1fixed 2.8.9-160000.4.1
Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\IO\BaseIO::loadConfiguration() validates GitHub OAuth tokens with the regex ^[.A-Za-z0-9_]+$ and interpolates rejected tokens into an UnexpectedValueException; GitHub Actions GITH
- affected < 2.8.9-160000.4.1fixed 2.8.9-160000.4.1
Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an untrusted repository other than Packagist.org or Private Packagist can cause Composer to write attacker-controlled files outside the vendor directory and outsi
- affected < 2.8.9-160000.4.1fixed 2.8.9-160000.4.1
Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, when Composer is run with -vvv debug verbosity, it could print a credential embedded in the username slot of a repository or package URL, such as a GitHub Personal Access Token in https://TOKEN@hos
- affected < 2.8.9-160000.4.1fixed 2.8.9-160000.4.1
Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containing .. path segments can resolve outside the package install directory and cause Composer's binary installation flow to chmod an existing host file to a world-re
- affected < 2.8.9-160000.4.1fixed 2.8.9-160000.4.1
Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $sourceReference parameter to a shell command without proper escaping, and additionally
- affected < 2.8.9-160000.4.1fixed 2.8.9-160000.4.1
Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::generateP4Command() method, which constructs shell commands by interpolating user-supplied Perforce connection parameters (port,
- affected < 2.8.9-160000.4.1fixed 2.8.9-160000.4.1
Composer is a dependency manager for PHP. In versions on the 2.x branch prior to 2.2.26 and 2.9.3, attackers controlling remote sources that Composer downloads from might in some way inject ANSI control characters in the terminal output of various Composer commands, causing mangl