<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T03:41:18.017121+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-composer-2026-59944</id>
    <title>BIT-composer-2026-59944 — Composer: CVE-2026-59946 fix bypass via symlinked package bin path</title>
    <updated>2026-10-04T03:41:18.022900+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: composer</p>
<p>Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3, a malicious or compromised dependency can bypass the earlier CVE-2026-59946 binary-path hardening because Composer validates literal parent-directory segments only during dependency resolution, while the symlink and installed-metadata paths described by the advisory skip that validation. A package can ship an in-package binary symlink that resolves outside its installation directory, or attacker-influenced vendor/composer/installed.json metadata can provide an escaping binary path during a reinstall or regeneration of missing vendor/bin entries. The installed-metadata path is reachable only when the vendor directory was not populated by the same validated install run, such as when it is restored from an untrusted cache, copied from an earlier build stage, carried over from an older Composer run, or writable by a lower-trust build step. Composer can follow the path, change the external target's permissions to make it world-readable and executable, and create a runnable vendor/bin proxy to that external file. The issue does not directly read or transmit data and does not by itself provide remote code execution. This issue is fixed in versions 2.2.30 and 2.10.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-composer-2026-59944"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-369805</id>
    <title>EUVD-2026-369805</title>
    <updated>2026-10-04T03:41:18.022955+00:00</updated>
    <content>EUVD-2026-369805</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-369805"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59944</id>
    <title>fkie_cve-2026-59944</title>
    <updated>2026-10-04T03:41:18.022971+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3, a malicious or compromised dependency can bypass the earlier CVE-2026-59946 binary-path hardening because Composer validates literal parent-directory segments only during dependency resolution, while the symlink and installed-metadata paths described by the advisory skip that validation. A package can ship an in-package binary symlink that resolves outside its installation directory, or attacker-influenced vendor/composer/installed.json metadata can provide an escaping binary path during a reinstall or regeneration of missing vendor/bin entries. The installed-metadata path is reachable only when the vendor directory was not populated by the same validated install run, such as when it is restored from an untrusted cache, copied from an earlier build stage, carried over from an older Composer run, or writable by a lower-trust build step. Composer can follow the path, change the external target's permissions to make it world-readable and executable, and create a runnable vendor/bin proxy to that external file. The issue does not directly read or transmit data and does not by itself provide remote code execution. This issue is fixed in versions 2.2.30 and 2.10.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-59944"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-96h3-5x6v-m776</id>
    <title>GHSA-96h3-5x6v-m776 — Composer: GHSA-gjfg-22fp-rrxx fix bypass via symlinked package bin path</title>
    <updated>2026-10-04T03:41:18.023001+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: composer/composer</p>
<p>## Summary</p>
<p>A malicious or compromised Composer package could, when installed as a dependency, cause Composer to change the permissions of a file outside that package's own directory and to register a runnable `vendor/bin` command that points at that outside file. This is a path traversal and link following issue. It is not remote code execution, the attacker gains no ability to read or receive your data directly. The risk is that a file which was readable only by its owner, but modifiable by Composer, can be made world readable and executable, which is enough to expose its contents on a shared or multi tenant host. The earlier hardening from GHSA-gjfg-22fp-rrxx can be bypassed, since it only rejected literal `..` path segments in a package's declared binaries, and was only applied in a single place during dependency resolution.</p>
<p>## Am I affected?</p>
<p>You can be affected if a malicious or compromised package, including a transitive dependency, is installed in your project, and either of the following is true:</p>
<p>- The dependency package ships one of its declared binaries as a symbolic link that resolves to a location outside the package's own directory. Nothing beyond a normal install or update is required.
- Or, the recorded metadata of your installed dependencies (`vendor/composer/installed.json`) declares a binary path that escapes the package's directory. Composer regenerates missing binaries from that recorded metadata at the end of an install, and uses this metadata for rei…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-96h3-5x6v-m776"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11633-1</id>
    <title>openSUSE-SU-2026:11633-1 — php-composer2-2.10.3-1.1 on GA media</title>
    <updated>2026-10-04T03:41:18.023044+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>php-composer2-2.10.3-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11633-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:63151</id>
    <title>RHSA-2026:63151 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-04T03:41:18.023062+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>composer: Composer: Security bypass allows execution of unauthorized binaries via symlinked paths composer: Composer: Arbitrary code execution via malicious Perforce source URL</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:63151"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23943-1</id>
    <title>SUSE-SU-2026:23943-1 — Security update for php-composer2</title>
    <updated>2026-10-04T03:41:18.023077+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for php-composer2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23943-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59944</id>
    <title>UBUNTU-CVE-2026-59944</title>
    <updated>2026-10-04T03:41:18.023090+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: composer, Ubuntu:Pro:18.04:LTS: composer, Ubuntu:Pro:20.04:LTS: composer, Ubuntu:Pro:22.04:LTS: composer, Ubuntu:Pro:24.04:LTS: composer, Ubuntu:26.04:LTS: composer</p>
<p>Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3, a malicious or compromised dependency can bypass the earlier CVE-2026-59946 binary-path hardening because Composer validates literal parent-directory segments only during dependency resolution, while the symlink and installed-metadata paths described by the advisory skip that validation. A package can ship an in-package binary symlink that resolves outside its installation directory, or attacker-influenced vendor/composer/installed.json metadata can provide an escaping binary path during a reinstall or regeneration of missing vendor/bin entries. The installed-metadata path is reachable only when the vendor directory was not populated by the same validated install run, such as when it is restored from an untrusted cache, copied from an earlier build stage, carried over from an older Composer run, or writable by a lower-trust build step. Composer can follow the path, change the external target's permissions to make it world-readable and executable, and create a runnable vendor/bin proxy to that external file. The issue does not directly read or transmit data and does not by itself provide remote code execution. This issue is fixed in versions 2.2.30 and 2.10.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59944"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3072</id>
    <title>WID-SEC-W-2026-3072 — Composer: Mehrere Schwachstellen</title>
    <updated>2026-10-04T03:41:18.023123+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Composer ausnutzen, um Sicherheitsvorkehrungen zu umgehenn und beliebigen Code auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3072"/>
  </entry>
</feed>
