<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:00:00 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-04878</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-04878</link>
      <description>bdu:2024-04878</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-04878</guid>
    </item>
    <item>
      <title>BIT-composer-2024-35241 — Composer vulnerable to command injection via malicious git branch name</title>
      <link>https://cve.radiocsirt.org/vuln/bit-composer-2024-35241</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: composer&lt;/p&gt;
&lt;p&gt;Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `status`, `reinstall` and `remove` commands with packages installed from source via git containing specially crafted branch names in the repository can be used to execute code. Patches for this issue are available in version 2.2.24 for 2.2 LTS or 2.7.7 for mainline. As a workaround, avoid installing dependencies via git by using `--prefer-dist` or the `preferred-install: dist` config setting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: composer&lt;/p&gt;
&lt;p&gt;Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `status`, `reinstall` and `remove` commands with packages installed from source via git containing specially crafted branch names in the repository can be used to execute code. Patches for this issue are available in version 2.2.24 for 2.2 LTS or 2.7.7 for mainline. As a workaround, avoid installing dependencies via git by using `--prefer-dist` or the `preferred-install: dist` config setting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-composer-2024-35241</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0836 — De multiples vulnérabilités ont été découvertes dans Tenable Security Center. Elles permettent à un attaquant de provoq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0836</link>
      <description>certfr-2025-avi-0836</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0836</guid>
    </item>
    <item>
      <title>CLEANSTART-2024-ND02975 — Composer is a dependency manager for PHP</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2024-nd02975</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: composer&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the composer package. Composer is a dependency manager for PHP.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: composer&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the composer package. Composer is a dependency manager for PHP.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2024-nd02975</guid>
    </item>
    <item>
      <title>EUVD-2026-232172</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-232172</link>
      <description>EUVD-2026-232172</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-232172</guid>
    </item>
    <item>
      <title>fkie_cve-2024-35241</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-35241</link>
      <description>&lt;p&gt;Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `status`, `reinstall` and `remove` commands with packages installed from source via git containing specially crafted branch names in the repository can be used to execute code. Patches for this issue are available in version 2.2.24 for 2.2 LTS or 2.7.7 for mainline. As a workaround, avoid installing dependencies via git by using `--prefer-dist` or the `preferred-install: dist` config setting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `status`, `reinstall` and `remove` commands with packages installed from source via git containing specially crafted branch names in the repository can be used to execute code. Patches for this issue are available in version 2.2.24 for 2.2 LTS or 2.7.7 for mainline. As a workaround, avoid installing dependencies via git by using `--prefer-dist` or the `preferred-install: dist` config setting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-35241</guid>
    </item>
    <item>
      <title>GHSA-47f6-5gq3-vx9c — Composer has a command injection via malicious git branch name</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-47f6-5gq3-vx9c</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: composer/composer&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The `status`, `reinstall` and `remove` commands with packages installed from source via git containing specially crafted branch names in the repository can be used to execute code.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;2.2.24 for 2.2 LTS or 2.7.7 for mainline&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Avoid installing dependencies via git by using `--prefer-dist` or the `preferred-install: dist` config setting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: composer/composer&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The `status`, `reinstall` and `remove` commands with packages installed from source via git containing specially crafted branch names in the repository can be used to execute code.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;2.2.24 for 2.2 LTS or 2.7.7 for mainline&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Avoid installing dependencies via git by using `--prefer-dist` or the `preferred-install: dist` config setting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-47f6-5gq3-vx9c</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14040-1 — php-composer2-2.7.7-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14040-1</link>
      <description>&lt;p&gt;php-composer2-2.7.7-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;php-composer2-2.7.7-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14040-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:2107-1 — Security update for php-composer2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:2107-1</link>
      <description>&lt;p&gt;Security update for php-composer2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for php-composer2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:2107-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-35241</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-35241</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: composer, Ubuntu:Pro:18.04:LTS: composer, Ubuntu:Pro:20.04:LTS: composer, Ubuntu:Pro:22.04:LTS: composer, Ubuntu:Pro:24.04:LTS: composer&lt;/p&gt;
&lt;p&gt;Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `status`, `reinstall` and `remove` commands with packages installed from source via git containing specially crafted branch names in the repository can be used to execute code. Patches for this issue are available in version 2.2.24 for 2.2 LTS or 2.7.7 for mainline. As a workaround, avoid installing dependencies via git by using `--prefer-dist` or the `preferred-install: dist` config setting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: composer, Ubuntu:Pro:18.04:LTS: composer, Ubuntu:Pro:20.04:LTS: composer, Ubuntu:Pro:22.04:LTS: composer, Ubuntu:Pro:24.04:LTS: composer&lt;/p&gt;
&lt;p&gt;Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `status`, `reinstall` and `remove` commands with packages installed from source via git containing specially crafted branch names in the repository can be used to execute code. Patches for this issue are available in version 2.2.24 for 2.2 LTS or 2.7.7 for mainline. As a workaround, avoid installing dependencies via git by using `--prefer-dist` or the `preferred-install: dist` config setting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-35241</guid>
    </item>
  </channel>
</rss>
