CVE-2023-43655: Debian Linux

High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.

Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed as a php file may be subject to a remote code execution vulnerability if PHP also has `register_argc_argv` enabled in php.ini. Versions 2.6.4, 2.2.22 and 1.10.27 patch this vulnerability. Users are advised to upgrade. Users unable to upgrade should make sure `register_argc_argv` is disabled in php.ini, and avoid publishing composer.phar to the web as this is not best practice.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Fedoraproject Fedora: version 37 only; version 38 only
  • Getcomposer Composer: before 1.10.27 (fixed in 1.10.27); from 2.0.0, before 2.2.21 (fixed in 2.2.21); from 2.3.0, before 2.6.4 (fixed in 2.6.4)

Published 2023-09-29. Last modified 2026-06-17.