SUSE-SU-2026:4283-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20264283-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4283-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:4283-1
Upstream
CVE (6)
Related
Published
2026-09-22T08:35:35Z
Modified
2026-09-23T09:15:06Z
Summary
Security update for php-composer2
Details

This update for php-composer2 fixes the following issues:

  • CVE-2026-45793: GitHub OAuth tokens failing regex validation can cause credential disclosure (bsc#1271504).
  • CVE-2026-59944: path traversal and link following issue can make files world readable and executable (bsc#1279898).
  • CVE-2026-59946: package bin entries with path segments can cause unintended host file permission modifications (bsc#1271152).
  • CVE-2026-59947: unsanitized URL credential handling in debug output within Composer can allow sensitive token disclosure (bsc#1271130).
  • CVE-2026-59948: missing package name validation during dependency resolution in Composer can allow path traversal (bsc#1271123).
  • CVE-2026-84361: arbitrary code execution via malicious Perforce source URL (bsc#1278257).

Changes for php-composer2:

  • version update to 2.2.30:
  • Fixed command injection via malicious Perforce url (GHSA-rvx4-ffvw-m9q3)
  • Sanitize URL-embedded usernames/token in a few more places (#13045)
  • Fixed matching of gitlab URLs to avoid possible credential leak to the wrong domain (#13042)
  • fix a regression on s390x due last change (bsc#1271729).

  • version update to 2.2.29:

  • Validate package names (GHSA-499r-g7pc-vmp9)
  • Validate package bin paths against path traversal (GHSA-gjfg-22fp-rrxx)
  • Sanitize URL-embedded usernames/token in verbose output (GHSA-g6xq-892h-64w3)
  • Only follow HTTP redirects from HTTP responses (#12948)
  • Prevent phar metadata unserialization on unsafe PHP versions (#12946)
  • Sanitize JSON parse errors in http responses to avoid leaking response body data (#12959)
  • Fixed GitHub token validation to be even more relaxed (#12856)
  • version update to 2.2.28.
References

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
php-composer2

Package

Name
php-composer2
Purl
pkg:rpm/suse/php-composer2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.2.30-150400.3.21.1

Ecosystem specific

{
    "binaries":  [
        {
            "php-composer2":  "2.2.30-150400.3.21.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4283-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
php-composer2

Package

Name
php-composer2
Purl
pkg:rpm/suse/php-composer2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.2.30-150400.3.21.1

Ecosystem specific

{
    "binaries":  [
        {
            "php-composer2":  "2.2.30-150400.3.21.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4283-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
php-composer2

Package

Name
php-composer2
Purl
pkg:rpm/suse/php-composer2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.2.30-150400.3.21.1

Ecosystem specific

{
    "binaries":  [
        {
            "php-composer2":  "2.2.30-150400.3.21.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4283-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
php-composer2

Package

Name
php-composer2
Purl
pkg:rpm/suse/php-composer2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.2.30-150400.3.21.1

Ecosystem specific

{
    "binaries":  [
        {
            "php-composer2":  "2.2.30-150400.3.21.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4283-1.json"
SUSE:Linux Enterprise Server 15 SP4-LTSS
php-composer2

Package

Name
php-composer2
Purl
pkg:rpm/suse/php-composer2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.2.30-150400.3.21.1

Ecosystem specific

{
    "binaries":  [
        {
            "php-composer2":  "2.2.30-150400.3.21.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4283-1.json"
SUSE:Linux Enterprise Server 15 SP5-LTSS
php-composer2

Package

Name
php-composer2
Purl
pkg:rpm/suse/php-composer2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.2.30-150400.3.21.1

Ecosystem specific

{
    "binaries":  [
        {
            "php-composer2":  "2.2.30-150400.3.21.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4283-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
php-composer2

Package

Name
php-composer2
Purl
pkg:rpm/suse/php-composer2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.2.30-150400.3.21.1

Ecosystem specific

{
    "binaries":  [
        {
            "php-composer2":  "2.2.30-150400.3.21.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4283-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
php-composer2

Package

Name
php-composer2
Purl
pkg:rpm/suse/php-composer2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.2.30-150400.3.21.1

Ecosystem specific

{
    "binaries":  [
        {
            "php-composer2":  "2.2.30-150400.3.21.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4283-1.json"