CVE-2026-45793

EUVD-2026-44723
Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\IO\BaseIO::loadConfiguration() validates GitHub OAuth tokens with the regex ^[.A-Za-z0-9_]+$ and interpolates rejected tokens into an UnexpectedValueException; GitHub Actions GITHUB_TOKEN values using the ghs_<id>_<base64url-JWT> format can contain -, fail validation, and be disclosed to stderr or CI logs. This issue is fixed in versions 1.10.28, 2.2.28, and 2.9.8.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 60.81%
Debian logo
Debian Releases
Debian Product
Codename
composer
bookworm
2.5.5-1+deb12u5
fixed
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
2.10.2-1
fixed
sid
2.10.2-1
fixed
trixie
2.8.8-1+deb13u3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
composer
bionic
needs-triage
focal
needs-triage
jammy
not-affected
noble
not-affected
questing
not-affected
resolute
not-affected
xenial
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
composer
Amazon Linux 2023
0:2.9.8-1.amzn2023.0.1
fixed