Known vulnerabilities in composer
Vendor:
Fedoraproject
Software:
composer
Software CPE:
cpe:2.3:o:fedoraproject:composer:*:*:*:*:*:fedora:*:*
Website:
https://getfedora.org/
Total vulnerabilities:
9
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
2.10.3-1.el10_3
2.10.3-1.el9
2.10.3-1.fc45
2.10.3-1.fc44
2.10.3-1.fc43
2.10.3-1.el10_2
2.10.3-1.el10_4
2.10.2-1.fc44
2.10.2-1.el9
2.10.2-1.el10_3
2.10.2-1.fc43
2.10.2-1.el10_2
2.10.1-1.fc43
2.10.1-1.el9
2.10.1-1.el10_2
2.10.1-1.fc44
2.10.1-1.el10_3
2.9.8-1.el10_1
2.9.8-1.fc44
2.9.8-1.el10_2
2.9.8-1.el9
2.9.8-1.fc43
2.9.8-1.el10_3
2.9.7-1.fc44
2.9.7-1.el9
2.9.7-1.el10_3
2.9.7-1.fc43
2.9.7-1.fc42
2.9.7-1.el10_2
2.9.7-1.el10_1
1.6.4-1.fc26
1.6.4-1.fc27
1.6.4-1.el7
1.6.4-1.fc28
2.3.5-1.fc35
2.3.5-1.fc36
2.3.5-1.el9
2.2.12-1.fc34
1.10.26-1.el7
2.0.13-1.fc34
2.0.13-1.fc33
1.10.22-1.el7
1.10.22-1.fc32
2.7.7-1.fc40
2.7.7-1.el9
2.7.7-1.fc39
2.6.5-1.fc38
2.6.5-1.fc39
2.6.5-1.fc37
2.6.5-1.el9
1.10.27-1.el7
2.6.4-1.fc37
2.6.4-1.el9
2.6.4-1.fc39
2.6.4-1.fc38
Vulnerabilities (9)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU146004 - Improper Link Resolution Before File Access ('Link Following') CVE-2026-59944 |
CWE-59 | Medium | 2.10.3-1.el9, 2.10.3-1.el10_2, 2.10.3-1.el10_3, 2.10.3-1.el10_4, 2.10.3-1.fc43, 2.10.3-1.fc44, 2.10.3-1.fc45 | 27.08.2026 |
SB20260827147 SB20260827152 SB20260827153 and 5 more |
||
| #VU125895 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2026-40176 |
CWE-78 | High | 2.9.7-1.el9, 2.9.7-1.el10_1, 2.9.7-1.el10_2, 2.9.7-1.el10_3, 2.9.7-1.fc42, 2.9.7-1.fc43, 2.9.7-1.fc44 | 14.04.2026 |
SB2026041445 SB2026041481 SB2026041482 and 8 more |
||
| #VU125894 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2026-40261 |
CWE-78 | High | 2.9.7-1.el9, 2.9.7-1.el10_1, 2.9.7-1.el10_2, 2.9.7-1.el10_3, 2.9.7-1.fc42, 2.9.7-1.fc43, 2.9.7-1.fc44 | 14.04.2026 |
SB2026041445 SB2026041481 SB2026041482 and 8 more |
||
| #VU91685 - Command injection CVE-2024-35242 |
CWE-77 | High | 2.7.7-1.el9, 2.7.7-1.fc39, 2.7.7-1.fc40 | 11.06.2024 |
SB2024061107 SB2024061108 SB2024061109 and 6 more |
||
| #VU91684 - Command injection CVE-2024-35241 |
CWE-77 | High | 2.7.7-1.el9, 2.7.7-1.fc39, 2.7.7-1.fc40 | 11.06.2024 |
SB2024061107 SB2024061108 SB2024061109 and 7 more |
||
| #VU81296 - Improper Control of Generation of Code ('Code Injection') CVE-2023-43655 |
CWE-94 | High | 1.10.27-1.el7, 2.6.4-1.el9, 2.6.4-1.fc37, 2.6.4-1.fc38, 2.6.4-1.fc39, 2.6.5-1.el9, 2.6.5-1.fc37, 2.6.5-1.fc38, 2.6.5-1.fc39 | 29.09.2023 |
SB2023092947 SB2023092956 SB2023092957 and 13 more |
||
| #VU62312 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2022-24828 |
CWE-78 | High | 1.10.26-1.el7, 2.2.12-1.fc34, 2.3.5-1.el9, 2.3.5-1.fc35, 2.3.5-1.fc36 | 14.04.2022 |
SB2022041401 SB2022042017 SB2022090517 and 7 more |
||
| #VU57096 - Command injection CVE-2021-41116 |
CWE-77 | High | 1.10.26-1.el7 | 06.10.2021 |
SB2021100610 SB2022042017 SB2022041434 |
||
| #VU52777 - Improper Control of Generation of Code ('Code Injection') CVE-2021-29472 |
CWE-94 | High | 1.10.22-1.el7, 1.10.22-1.fc32, 2.0.13-1.fc33, 2.0.13-1.fc34 | 30.04.2021 |
SB2021043007 SB2021043008 SB2021051726 and 3 more |