Improper input validation in composer - CVE-2025-67746
Published: April 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper neutralization of terminal control sequences in terminal output handling when processing data from remote sources. A remote attacker can inject ANSI control characters to cause a denial of service.
The issue may also mangle terminal output and lead to user confusion.
Affected software
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Web and Scripting Module
openSUSE Leap
Anolis OS
php-composer2
composer
composer-doc
How to mitigate CVE-2025-67746
php-composer2 - addressed in versions 2.2.3-150400.3.15.1, 2.6.4-150600.3.6.1, 2.6.4-150600.3.12.1
composer - update to 2.7.1-5
composer-doc - update to 2.7.1-5