Количество 6
Количество 6
CVE-2026-45793
Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\IO\BaseIO::loadConfiguration() validates GitHub OAuth tokens with the regex ^[.A-Za-z0-9_]+$ and interpolates rejected tokens into an UnexpectedValueException; GitHub Actions GITHUB_TOKEN values using the ghs_<id>_<base64url-JWT> format can contain -, fail validation, and be disclosed to stderr or CI logs. This issue is fixed in versions 1.10.28, 2.2.28, and 2.9.8.
CVE-2026-45793
Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\IO\BaseIO::loadConfiguration() validates GitHub OAuth tokens with the regex ^[.A-Za-z0-9_]+$ and interpolates rejected tokens into an UnexpectedValueException; GitHub Actions GITHUB_TOKEN values using the ghs_<id>_<base64url-JWT> format can contain -, fail validation, and be disclosed to stderr or CI logs. This issue is fixed in versions 1.10.28, 2.2.28, and 2.9.8.
CVE-2026-45793
Composer is a dependency Manager for the PHP language. Prior to 1.10.2 ...
GHSA-f9f8-rm49-7jv2
Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logs
openSUSE-SU-2026:21520-1
Security update for php-composer2
SUSE-SU-2026:3105-1
Security update for php-composer2
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-45793 Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\IO\BaseIO::loadConfiguration() validates GitHub OAuth tokens with the regex ^[.A-Za-z0-9_]+$ and interpolates rejected tokens into an UnexpectedValueException; GitHub Actions GITHUB_TOKEN values using the ghs_<id>_<base64url-JWT> format can contain -, fail validation, and be disclosed to stderr or CI logs. This issue is fixed in versions 1.10.28, 2.2.28, and 2.9.8. | CVSS3: 7.5 | 1% Низкий | 29 дней назад | |
CVE-2026-45793 Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\IO\BaseIO::loadConfiguration() validates GitHub OAuth tokens with the regex ^[.A-Za-z0-9_]+$ and interpolates rejected tokens into an UnexpectedValueException; GitHub Actions GITHUB_TOKEN values using the ghs_<id>_<base64url-JWT> format can contain -, fail validation, and be disclosed to stderr or CI logs. This issue is fixed in versions 1.10.28, 2.2.28, and 2.9.8. | CVSS3: 7.5 | 1% Низкий | 29 дней назад | |
CVE-2026-45793 Composer is a dependency Manager for the PHP language. Prior to 1.10.2 ... | CVSS3: 7.5 | 1% Низкий | 29 дней назад | |
GHSA-f9f8-rm49-7jv2 Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logs | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
openSUSE-SU-2026:21520-1 Security update for php-composer2 | 10 дней назад | |||
SUSE-SU-2026:3105-1 Security update for php-composer2 | 27 дней назад |
Уязвимостей на страницу