Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-45793

Опубликовано: 15 июл. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\IO\BaseIO::loadConfiguration() validates GitHub OAuth tokens with the regex ^[.A-Za-z0-9_]+$ and interpolates rejected tokens into an UnexpectedValueException; GitHub Actions GITHUB_TOKEN values using the ghs__ format can contain -, fail validation, and be disclosed to stderr or CI logs. This issue is fixed in versions 1.10.28, 2.2.28, and 2.9.8.

EPSS

Процентиль: 53%
0.00797
Низкий

7.5 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.5
ubuntu
29 дней назад

Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\IO\BaseIO::loadConfiguration() validates GitHub OAuth tokens with the regex ^[.A-Za-z0-9_]+$ and interpolates rejected tokens into an UnexpectedValueException; GitHub Actions GITHUB_TOKEN values using the ghs_<id>_<base64url-JWT> format can contain -, fail validation, and be disclosed to stderr or CI logs. This issue is fixed in versions 1.10.28, 2.2.28, and 2.9.8.

CVSS3: 7.5
debian
29 дней назад

Composer is a dependency Manager for the PHP language. Prior to 1.10.2 ...

CVSS3: 7.5
github
3 месяца назад

Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logs

suse-cvrf
10 дней назад

Security update for php-composer2

suse-cvrf
27 дней назад

Security update for php-composer2

EPSS

Процентиль: 53%
0.00797
Низкий

7.5 High

CVSS3

Дефекты

CWE-200