SB2026093043 - SUSE update for php-composer2



SB2026093043 - SUSE update for php-composer2

Published: September 30, 2026

Security Bulletin ID SB2026093043
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 67% Low 33%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 vulnerabilities.


1) Information disclosure (CVE-ID: CVE-2026-45793)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to exposure of sensitive information in ComposerIOBaseIO::loadConfiguration() when validating GitHub OAuth tokens. A remote attacker can supply a token containing invalid characters to disclose sensitive information.

The issue is triggered when the rejected token is interpolated into an exception message and written to stderr, which may be captured in GitHub Actions logs.


2) Link following (CVE-ID: CVE-2026-59944)

CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to path traversal and improper link resolution in package binary handling when installing a malicious or compromised dependency package. A remote attacker can supply a specially crafted package or manipulated installed dependency metadata to cause Composer to change permissions on a file outside the package directory and expose its contents to disclose sensitive information.

User interaction is required to install or update dependencies. The issue can be triggered through a symbolic link that resolves outside the package directory or through crafted vendor/composer/installed.json metadata when binaries are regenerated from an existing vendor directory.


3) Inclusion of Sensitive Information in Log Files (CVE-ID: CVE-2026-59947)

CWE-ID: CWE-532 - Information Exposure Through Log Files

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to insertion of sensitive information into log files in Composer debug output when handling repository or package URLs with credentials embedded in the username field. A local user can run Composer with debug verbosity and cause an embedded access token to be written to verbose logs to disclose sensitive information.

Exposure occurs only when a credential is embedded in a handled URL, placed in the username slot, and the debug output is retained or shared where others can read it.


Remediation

Install update from vendor's website.