Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59947

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 4.7
EPSS Низкий

Описание

Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, when Composer is run with -vvv debug verbosity, it could print a credential embedded in the username slot of a repository or package URL, such as a GitHub Personal Access Token in https://TOKEN@host/, to debug output because AuthHelper, Url::sanitize, and ProcessExecutor did not sanitize username-only URL credentials. This issue is fixed in versions 2.2.29 and 2.10.2.

A flaw was found in Composer, a dependency manager for the PHP language. When Composer is executed with the -vvv debug verbosity option, it can inadvertently expose sensitive credentials, such as a GitHub Personal Access Token, by printing them in the debug output. This occurs because certain internal components fail to properly sanitize username-only URL credentials. A local user with access to the debug output could exploit this to gain unauthorized access to resources.

Отчет

Red Hat ships Composer version 2.10.2 in its products, which already includes the fix for this issue. No action is required.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Hardened ImagescomposerNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-215
https://bugzilla.redhat.com/show_bug.cgi?id=2498208composer/composer: Composer: Information disclosure of credentials via debug output

EPSS

Процентиль: 2%
0.0012
Низкий

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
ubuntu
26 дней назад

Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, when Composer is run with -vvv debug verbosity, it could print a credential embedded in the username slot of a repository or package URL, such as a GitHub Personal Access Token in https://TOKEN@host/, to debug output because AuthHelper, Url::sanitize, and ProcessExecutor did not sanitize username-only URL credentials. This issue is fixed in versions 2.2.29 and 2.10.2.

CVSS3: 4.7
nvd
26 дней назад

Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, when Composer is run with -vvv debug verbosity, it could print a credential embedded in the username slot of a repository or package URL, such as a GitHub Personal Access Token in https://TOKEN@host/, to debug output because AuthHelper, Url::sanitize, and ProcessExecutor did not sanitize username-only URL credentials. This issue is fixed in versions 2.2.29 and 2.10.2.

CVSS3: 4.7
debian
26 дней назад

Composer is a dependency Manager for the PHP language. Prior to 2.2.29 ...

CVSS3: 4.7
github
14 дней назад

Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)

suse-cvrf
17 дней назад

Security update for php-composer2

EPSS

Процентиль: 2%
0.0012
Низкий

4.7 Medium

CVSS3