CVE-2026-45793: Composer

High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.

Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\IO\BaseIO::loadConfiguration() validates GitHub OAuth tokens with the regex ^[.A-Za-z0-9_]+$ and interpolates rejected tokens into an UnexpectedValueException; GitHub Actions GITHUB_TOKEN values using the ghs_<id>_<base64url-JWT> format can contain -, fail validation, and be disclosed to stderr or CI logs. This issue is fixed in versions 1.10.28, 2.2.28, and 2.9.8.

Affected products

  • Composer Composer: from 1.0, before 1.10.28 (fixed in 1.10.28); from 2.0.0, before 2.2.28 (fixed in 2.2.28); from 2.3.0, before 2.9.8 (fixed in 2.9.8)

Published 2026-07-15. Last modified 2026-07-15.