<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T22:26:22.587085+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-04880</id>
    <title>bdu:2024-04880</title>
    <updated>2026-10-03T22:26:22.708794+00:00</updated>
    <content>bdu:2024-04880</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-04880"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-composer-2024-35242</id>
    <title>BIT-composer-2024-35242 — Composer vulnerable to command injection via malicious git/hg branch names</title>
    <updated>2026-10-03T22:26:22.708872+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: composer</p>
<p>Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `composer install` command running inside a git/hg repository which has specially crafted branch names can lead to command injection. This requires cloning untrusted repositories. Patches are available in version 2.2.24 for 2.2 LTS or 2.7.7 for mainline. As a workaround, avoid cloning potentially compromised repositories.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-composer-2024-35242"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0836</id>
    <title>certfr-2025-avi-0836 — De multiples vulnérabilités ont été découvertes dans Tenable Security Center. Elles permettent à un attaquant de provoq…</title>
    <updated>2026-10-03T22:26:22.708917+00:00</updated>
    <content>certfr-2025-avi-0836</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0836"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2024-dd29597</id>
    <title>CLEANSTART-2024-DD29597 — Composer is a dependency manager for PHP</title>
    <updated>2026-10-03T22:26:22.708937+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: composer</p>
<p>Security vulnerability affects the composer package. Composer is a dependency manager for PHP.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2024-dd29597"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-217420</id>
    <title>EUVD-2026-217420</title>
    <updated>2026-10-03T22:26:22.708958+00:00</updated>
    <content>EUVD-2026-217420</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-217420"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-35242</id>
    <title>fkie_cve-2024-35242</title>
    <updated>2026-10-03T22:26:22.708970+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `composer install` command running inside a git/hg repository which has specially crafted branch names can lead to command injection. This requires cloning untrusted repositories. Patches are available in version 2.2.24 for 2.2 LTS or 2.7.7 for mainline. As a workaround, avoid cloning potentially compromised repositories.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-35242"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v9qv-c7wm-wgmf</id>
    <title>GHSA-v9qv-c7wm-wgmf — Composer has multiple command injections via malicious git/hg branch names</title>
    <updated>2026-10-03T22:26:22.708993+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: composer/composer</p>
<p>### Impact</p>
<p>The `composer install` command running inside a git/hg repository which has specially crafted branch names can lead to command injection. So this requires cloning untrusted repositories.</p>
<p>### Patches</p>
<p>2.2.24 for 2.2 LTS or 2.7.7 for mainline</p>
<p>### Workarounds</p>
<p>Avoid cloning potentially compromised repositories.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v9qv-c7wm-wgmf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14040-1</id>
    <title>openSUSE-SU-2024:14040-1 — php-composer2-2.7.7-1.1 on GA media</title>
    <updated>2026-10-03T22:26:22.709020+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>php-composer2-2.7.7-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14040-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:2107-1</id>
    <title>SUSE-SU-2024:2107-1 — Security update for php-composer2</title>
    <updated>2026-10-03T22:26:22.709039+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for php-composer2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:2107-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-35242</id>
    <title>UBUNTU-CVE-2024-35242</title>
    <updated>2026-10-03T22:26:22.709054+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: composer, Ubuntu:Pro:18.04:LTS: composer, Ubuntu:Pro:20.04:LTS: composer, Ubuntu:Pro:22.04:LTS: composer, Ubuntu:Pro:24.04:LTS: composer</p>
<p>Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `composer install` command running inside a git/hg repository which has specially crafted branch names can lead to command injection. This requires cloning untrusted repositories. Patches are available in version 2.2.24 for 2.2 LTS or 2.7.7 for mainline. As a workaround, avoid cloning potentially compromised repositories.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-35242"/>
  </entry>
</feed>
