<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 21:11:48 +0000</lastBuildDate>
    <item>
      <title>BIT-composer-2026-59948 — Composer: Arbitrary file write outside vendor via malicious transitive package name</title>
      <link>https://cve.radiocsirt.org/vuln/bit-composer-2026-59948</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: composer&lt;/p&gt;
&lt;p&gt;Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an untrusted repository other than Packagist.org or Private Packagist can cause Composer to write attacker-controlled files outside the vendor directory and outside the project during install or update by using an invalid package name that is not correctly validated before dependency-resolution results are written or installed. This issue is fixed in versions 2.2.29 and 2.10.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: composer&lt;/p&gt;
&lt;p&gt;Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an untrusted repository other than Packagist.org or Private Packagist can cause Composer to write attacker-controlled files outside the vendor directory and outside the project during install or update by using an invalid package name that is not correctly validated before dependency-resolution results are written or installed. This issue is fixed in versions 2.2.29 and 2.10.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-composer-2026-59948</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-UO36556 — Security fix for CVE-2026-59948 applied in: composer 2.10.2-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-uo36556</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: composer&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the composer package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: composer&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the composer package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-uo36556</guid>
    </item>
    <item>
      <title>EUVD-2026-335340</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-335340</link>
      <description>EUVD-2026-335340</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-335340</guid>
    </item>
    <item>
      <title>fkie_cve-2026-59948</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59948</link>
      <description>&lt;p&gt;Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an untrusted repository other than Packagist.org or Private Packagist can cause Composer to write attacker-controlled files outside the vendor directory and outside the project during install or update by using an invalid package name that is not correctly validated before dependency-resolution results are written or installed. This issue is fixed in versions 2.2.29 and 2.10.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an untrusted repository other than Packagist.org or Private Packagist can cause Composer to write attacker-controlled files outside the vendor directory and outside the project during install or update by using an invalid package name that is not correctly validated before dependency-resolution results are written or installed. This issue is fixed in versions 2.2.29 and 2.10.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-59948</guid>
    </item>
    <item>
      <title>GHSA-499r-g7pc-vmp9 — Composer: Arbitrary file write outside vendor via malicious transitive package name</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-499r-g7pc-vmp9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: composer/composer&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A maliciously crafted package, published on an untrusted third party repository other than Packagist.org or Private Packagist, can cause Composer to write files outside the `vendor/` directory and outside your project, with attacker-controlled content, during a normal `install` or `update` through using an invalid package name, which was not correctly validated by Composer.&lt;/p&gt;
&lt;p&gt;This is an arbitrary file write that can be used to execute code outside the Composer project&amp;#39;s context in which you expected the package code to execute (for example by writing shell startup files, SSH `authorized_keys`, or a cron entry). It is a supply-chain issue: it requires a malicious or compromised package to be present in the dependency graph, it is not otherwise remotely exploitable against a machine.&lt;/p&gt;
&lt;p&gt;The fix makes Composer validate every package produced by dependency resolution before anything is written to `composer.lock` or installed, and abort with a security error if a package name is not a valid `vendor/package` name.&lt;/p&gt;
&lt;p&gt;## Am I affected?&lt;/p&gt;
&lt;p&gt;You may be affected if you install packages from an untrusted third party repository, which does not sufficiently validate package names. Packagist.org and Private Packagist are safe, as they validate package names correctly.&lt;/p&gt;
&lt;p&gt;## Patched versions&lt;/p&gt;
&lt;p&gt;Fixed in **2.2.29** and **2.10.2**. Composer 1.x is also affected and you should move to a safe 2.x release.&lt;/p&gt;
&lt;p&gt;## Workarounds&lt;/p&gt;
&lt;p&gt;Do not use untrusted package repositories. If you have to, mirror them t…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: composer/composer&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A maliciously crafted package, published on an untrusted third party repository other than Packagist.org or Private Packagist, can cause Composer to write files outside the `vendor/` directory and outside your project, with attacker-controlled content, during a normal `install` or `update` through using an invalid package name, which was not correctly validated by Composer.&lt;/p&gt;
&lt;p&gt;This is an arbitrary file write that can be used to execute code outside the Composer project&amp;#39;s context in which you expected the package code to execute (for example by writing shell startup files, SSH `authorized_keys`, or a cron entry). It is a supply-chain issue: it requires a malicious or compromised package to be present in the dependency graph, it is not otherwise remotely exploitable against a machine.&lt;/p&gt;
&lt;p&gt;The fix makes Composer validate every package produced by dependency resolution before anything is written to `composer.lock` or installed, and abort with a security error if a package name is not a valid `vendor/package` name.&lt;/p&gt;
&lt;p&gt;## Am I affected?&lt;/p&gt;
&lt;p&gt;You may be affected if you install packages from an untrusted third party repository, which does not sufficiently validate package names. Packagist.org and Private Packagist are safe, as they validate package names correctly.&lt;/p&gt;
&lt;p&gt;## Patched versions&lt;/p&gt;
&lt;p&gt;Fixed in **2.2.29** and **2.10.2**. Composer 1.x is also affected and you should move to a safe 2.x release.&lt;/p&gt;
&lt;p&gt;## Workarounds&lt;/p&gt;
&lt;p&gt;Do not use untrusted package repositories. If you have to, mirror them t…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-499r-g7pc-vmp9</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11268-1 — php-composer2-2.10.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11268-1</link>
      <description>&lt;p&gt;php-composer2-2.10.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;php-composer2-2.10.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11268-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23116-1 — Security update for php-composer2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23116-1</link>
      <description>&lt;p&gt;Security update for php-composer2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for php-composer2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23116-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-59948</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59948</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: composer, Ubuntu:Pro:18.04:LTS: composer, Ubuntu:Pro:20.04:LTS: composer, Ubuntu:Pro:22.04:LTS: composer, Ubuntu:Pro:24.04:LTS: composer, Ubuntu:25.10: composer, Ubuntu:26.04:LTS: composer&lt;/p&gt;
&lt;p&gt;Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an untrusted repository other than Packagist.org or Private Packagist can cause Composer to write attacker-controlled files outside the vendor directory and outside the project during install or update by using an invalid package name that is not correctly validated before dependency-resolution results are written or installed. This issue is fixed in versions 2.2.29 and 2.10.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: composer, Ubuntu:Pro:18.04:LTS: composer, Ubuntu:Pro:20.04:LTS: composer, Ubuntu:Pro:22.04:LTS: composer, Ubuntu:Pro:24.04:LTS: composer, Ubuntu:25.10: composer, Ubuntu:26.04:LTS: composer&lt;/p&gt;
&lt;p&gt;Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an untrusted repository other than Packagist.org or Private Packagist can cause Composer to write attacker-controlled files outside the vendor directory and outside the project during install or update by using an invalid package name that is not correctly validated before dependency-resolution results are written or installed. This issue is fixed in versions 2.2.29 and 2.10.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59948</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2235 — Composer: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2235</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Composer ausnutzen, um Sicherheitsmechanismen zu umgehen, um beliebige Dateien zu schreiben oder um Informationen offenzulegen. Zur erfolgreichen Ausnutzung sind teilweise bestimmte Konfigurationen erforderlich.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Composer ausnutzen, um Sicherheitsmechanismen zu umgehen, um beliebige Dateien zu schreiben oder um Informationen offenzulegen. Zur erfolgreichen Ausnutzung sind teilweise bestimmte Konfigurationen erforderlich.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2235</guid>
    </item>
  </channel>
</rss>
