<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:43:59 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-04880</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-04880</link>
      <description>bdu:2024-04880</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-04880</guid>
    </item>
    <item>
      <title>BIT-composer-2024-35242 — Composer vulnerable to command injection via malicious git/hg branch names</title>
      <link>https://cve.radiocsirt.org/vuln/bit-composer-2024-35242</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: composer&lt;/p&gt;
&lt;p&gt;Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `composer install` command running inside a git/hg repository which has specially crafted branch names can lead to command injection. This requires cloning untrusted repositories. Patches are available in version 2.2.24 for 2.2 LTS or 2.7.7 for mainline. As a workaround, avoid cloning potentially compromised repositories.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: composer&lt;/p&gt;
&lt;p&gt;Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `composer install` command running inside a git/hg repository which has specially crafted branch names can lead to command injection. This requires cloning untrusted repositories. Patches are available in version 2.2.24 for 2.2 LTS or 2.7.7 for mainline. As a workaround, avoid cloning potentially compromised repositories.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-composer-2024-35242</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0836 — De multiples vulnérabilités ont été découvertes dans Tenable Security Center. Elles permettent à un attaquant de provoq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0836</link>
      <description>certfr-2025-avi-0836</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0836</guid>
    </item>
    <item>
      <title>CLEANSTART-2024-DD29597 — Composer is a dependency manager for PHP</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2024-dd29597</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: composer&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the composer package. Composer is a dependency manager for PHP.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: composer&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the composer package. Composer is a dependency manager for PHP.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2024-dd29597</guid>
    </item>
    <item>
      <title>EUVD-2026-217420</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-217420</link>
      <description>EUVD-2026-217420</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-217420</guid>
    </item>
    <item>
      <title>fkie_cve-2024-35242</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-35242</link>
      <description>&lt;p&gt;Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `composer install` command running inside a git/hg repository which has specially crafted branch names can lead to command injection. This requires cloning untrusted repositories. Patches are available in version 2.2.24 for 2.2 LTS or 2.7.7 for mainline. As a workaround, avoid cloning potentially compromised repositories.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `composer install` command running inside a git/hg repository which has specially crafted branch names can lead to command injection. This requires cloning untrusted repositories. Patches are available in version 2.2.24 for 2.2 LTS or 2.7.7 for mainline. As a workaround, avoid cloning potentially compromised repositories.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-35242</guid>
    </item>
    <item>
      <title>GHSA-v9qv-c7wm-wgmf — Composer has multiple command injections via malicious git/hg branch names</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v9qv-c7wm-wgmf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: composer/composer&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The `composer install` command running inside a git/hg repository which has specially crafted branch names can lead to command injection. So this requires cloning untrusted repositories.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;2.2.24 for 2.2 LTS or 2.7.7 for mainline&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Avoid cloning potentially compromised repositories.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: composer/composer&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The `composer install` command running inside a git/hg repository which has specially crafted branch names can lead to command injection. So this requires cloning untrusted repositories.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;2.2.24 for 2.2 LTS or 2.7.7 for mainline&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Avoid cloning potentially compromised repositories.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v9qv-c7wm-wgmf</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14040-1 — php-composer2-2.7.7-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14040-1</link>
      <description>&lt;p&gt;php-composer2-2.7.7-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;php-composer2-2.7.7-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14040-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:2107-1 — Security update for php-composer2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:2107-1</link>
      <description>&lt;p&gt;Security update for php-composer2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for php-composer2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:2107-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-35242</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-35242</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: composer, Ubuntu:Pro:18.04:LTS: composer, Ubuntu:Pro:20.04:LTS: composer, Ubuntu:Pro:22.04:LTS: composer, Ubuntu:Pro:24.04:LTS: composer&lt;/p&gt;
&lt;p&gt;Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `composer install` command running inside a git/hg repository which has specially crafted branch names can lead to command injection. This requires cloning untrusted repositories. Patches are available in version 2.2.24 for 2.2 LTS or 2.7.7 for mainline. As a workaround, avoid cloning potentially compromised repositories.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: composer, Ubuntu:Pro:18.04:LTS: composer, Ubuntu:Pro:20.04:LTS: composer, Ubuntu:Pro:22.04:LTS: composer, Ubuntu:Pro:24.04:LTS: composer&lt;/p&gt;
&lt;p&gt;Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `composer install` command running inside a git/hg repository which has specially crafted branch names can lead to command injection. This requires cloning untrusted repositories. Patches are available in version 2.2.24 for 2.2 LTS or 2.7.7 for mainline. As a workaround, avoid cloning potentially compromised repositories.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-35242</guid>
    </item>
  </channel>
</rss>
