Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-45793

Опубликовано: 15 июл. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 7.5

Описание

Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\IO\BaseIO::loadConfiguration() validates GitHub OAuth tokens with the regex ^[.A-Za-z0-9_]+$ and interpolates rejected tokens into an UnexpectedValueException; GitHub Actions GITHUB_TOKEN values using the ghs__ format can contain -, fail validation, and be disclosed to stderr or CI logs. This issue is fixed in versions 1.10.28, 2.2.28, and 2.9.8.

РелизСтатусПримечание
devel

not-affected

esm-apps-legacy/xenial

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

not-affected

esm-apps/noble

not-affected

esm-apps/resolute

not-affected

jammy

not-affected

2.2.6-2ubuntu4
noble

not-affected

questing

not-affected

Показывать по

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
29 дней назад

Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\IO\BaseIO::loadConfiguration() validates GitHub OAuth tokens with the regex ^[.A-Za-z0-9_]+$ and interpolates rejected tokens into an UnexpectedValueException; GitHub Actions GITHUB_TOKEN values using the ghs_<id>_<base64url-JWT> format can contain -, fail validation, and be disclosed to stderr or CI logs. This issue is fixed in versions 1.10.28, 2.2.28, and 2.9.8.

CVSS3: 7.5
debian
29 дней назад

Composer is a dependency Manager for the PHP language. Prior to 1.10.2 ...

CVSS3: 7.5
github
3 месяца назад

Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logs

suse-cvrf
10 дней назад

Security update for php-composer2

suse-cvrf
27 дней назад

Security update for php-composer2

7.5 High

CVSS3