Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-45793

Опубликовано: 15 июл. 2026
Источник: debian
EPSS Низкий

Описание

Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\IO\BaseIO::loadConfiguration() validates GitHub OAuth tokens with the regex ^[.A-Za-z0-9_]+$ and interpolates rejected tokens into an UnexpectedValueException; GitHub Actions GITHUB_TOKEN values using the ghs_<id>_<base64url-JWT> format can contain -, fail validation, and be disclosed to stderr or CI logs. This issue is fixed in versions 1.10.28, 2.2.28, and 2.9.8.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
composerfixed2.10.0-1package
composerfixed2.8.8-1+deb13u3trixiepackage
composerfixed2.5.5-1+deb12u5bookwormpackage

Примечания

  • https://github.com/composer/composer/security/advisories/GHSA-f9f8-rm49-7jv2

EPSS

Процентиль: 53%
0.00797
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
29 дней назад

Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\IO\BaseIO::loadConfiguration() validates GitHub OAuth tokens with the regex ^[.A-Za-z0-9_]+$ and interpolates rejected tokens into an UnexpectedValueException; GitHub Actions GITHUB_TOKEN values using the ghs_<id>_<base64url-JWT> format can contain -, fail validation, and be disclosed to stderr or CI logs. This issue is fixed in versions 1.10.28, 2.2.28, and 2.9.8.

CVSS3: 7.5
nvd
29 дней назад

Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\IO\BaseIO::loadConfiguration() validates GitHub OAuth tokens with the regex ^[.A-Za-z0-9_]+$ and interpolates rejected tokens into an UnexpectedValueException; GitHub Actions GITHUB_TOKEN values using the ghs_<id>_<base64url-JWT> format can contain -, fail validation, and be disclosed to stderr or CI logs. This issue is fixed in versions 1.10.28, 2.2.28, and 2.9.8.

CVSS3: 7.5
github
3 месяца назад

Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logs

suse-cvrf
10 дней назад

Security update for php-composer2

suse-cvrf
27 дней назад

Security update for php-composer2

EPSS

Процентиль: 53%
0.00797
Низкий