<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T09:08:57.404992+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-04878</id>
    <title>bdu:2024-04878</title>
    <updated>2026-10-03T09:08:57.523467+00:00</updated>
    <content>bdu:2024-04878</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-04878"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-composer-2024-35241</id>
    <title>BIT-composer-2024-35241 — Composer vulnerable to command injection via malicious git branch name</title>
    <updated>2026-10-03T09:08:57.523504+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: composer</p>
<p>Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `status`, `reinstall` and `remove` commands with packages installed from source via git containing specially crafted branch names in the repository can be used to execute code. Patches for this issue are available in version 2.2.24 for 2.2 LTS or 2.7.7 for mainline. As a workaround, avoid installing dependencies via git by using `--prefer-dist` or the `preferred-install: dist` config setting.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-composer-2024-35241"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0836</id>
    <title>certfr-2025-avi-0836 — De multiples vulnérabilités ont été découvertes dans Tenable Security Center. Elles permettent à un attaquant de provoq…</title>
    <updated>2026-10-03T09:08:57.523539+00:00</updated>
    <content>certfr-2025-avi-0836</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0836"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2024-nd02975</id>
    <title>CLEANSTART-2024-ND02975 — Composer is a dependency manager for PHP</title>
    <updated>2026-10-03T09:08:57.523558+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: composer</p>
<p>Security vulnerability affects the composer package. Composer is a dependency manager for PHP.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2024-nd02975"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-232172</id>
    <title>EUVD-2026-232172</title>
    <updated>2026-10-03T09:08:57.523579+00:00</updated>
    <content>EUVD-2026-232172</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-232172"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-35241</id>
    <title>fkie_cve-2024-35241</title>
    <updated>2026-10-03T09:08:57.523590+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `status`, `reinstall` and `remove` commands with packages installed from source via git containing specially crafted branch names in the repository can be used to execute code. Patches for this issue are available in version 2.2.24 for 2.2 LTS or 2.7.7 for mainline. As a workaround, avoid installing dependencies via git by using `--prefer-dist` or the `preferred-install: dist` config setting.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-35241"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-47f6-5gq3-vx9c</id>
    <title>GHSA-47f6-5gq3-vx9c — Composer has a command injection via malicious git branch name</title>
    <updated>2026-10-03T09:08:57.523613+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: composer/composer</p>
<p>### Impact</p>
<p>The `status`, `reinstall` and `remove` commands with packages installed from source via git containing specially crafted branch names in the repository can be used to execute code.</p>
<p>### Patches</p>
<p>2.2.24 for 2.2 LTS or 2.7.7 for mainline</p>
<p>### Workarounds</p>
<p>Avoid installing dependencies via git by using `--prefer-dist` or the `preferred-install: dist` config setting.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-47f6-5gq3-vx9c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14040-1</id>
    <title>openSUSE-SU-2024:14040-1 — php-composer2-2.7.7-1.1 on GA media</title>
    <updated>2026-10-03T09:08:57.523638+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>php-composer2-2.7.7-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14040-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:2107-1</id>
    <title>SUSE-SU-2024:2107-1 — Security update for php-composer2</title>
    <updated>2026-10-03T09:08:57.523656+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for php-composer2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:2107-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-35241</id>
    <title>UBUNTU-CVE-2024-35241</title>
    <updated>2026-10-03T09:08:57.523671+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: composer, Ubuntu:Pro:18.04:LTS: composer, Ubuntu:Pro:20.04:LTS: composer, Ubuntu:Pro:22.04:LTS: composer, Ubuntu:Pro:24.04:LTS: composer</p>
<p>Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `status`, `reinstall` and `remove` commands with packages installed from source via git containing specially crafted branch names in the repository can be used to execute code. Patches for this issue are available in version 2.2.24 for 2.2 LTS or 2.7.7 for mainline. As a workaround, avoid installing dependencies via git by using `--prefer-dist` or the `preferred-install: dist` config setting.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-35241"/>
  </entry>
</feed>
