gpp_maybe
Security update for php-composer2
SUSE-SLE-Module-Web-Scripting-15-SP7-2026-3105
This update for php-composer2 fixes the following issues: - CVE-2026-45793: Github Actions issued `GITHUB_TOKEN` disclosure in GitHub Actions logs (bsc#1271504). - CVE-2026-59946: path traversal in package `bin` field lets dependencies `chmod` arbitrary host files (bsc#1271151). - CVE-2026-59947: URL-embedded HTTP-Basic username leaks to verbose logs (bsc#1271129). - CVE-2026-59948: arbitrary file write outside `vendor`directory via malicious transitive package name (bsc#1271122).
-
Release DateJul 17 2026
-
ReferencesBugzilla: 1271122, 1271129, 1271151, 1271504
CVEs: CVE-2024-35241, CVE-2024-35242, CVE-2025-67746, CVE-2026-40176, CVE-2026-40261, CVE-2026-45793, CVE-2026-59946, CVE-2026-59947, CVE-2026-59948 -
Typesecurity
-
Severityimportant
cloud_download Downloads
To download packages, you need to log in and have a valid subscription.
Web and Scripting Module 15.7 ppc64le
-
Packages
Web and Scripting Module 15.7 aarch64
-
Packages
Web and Scripting Module 15.7 s390x
-
Packages
Web and Scripting Module 15.7 x86_64
-
Packages