SUSE-SU-2026:4589-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20264589-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4589-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:4589-1
Upstream
CVE (3)
Related
Published
2026-10-08T12:15:37Z
Modified
2026-10-09T18:15:03Z
Summary
Security update for php-composer2
Details

This update for php-composer2 fixes the following issues:

  • CVE-2026-59946: package bin entries with path segments can cause unintended host file permission modifications (bsc#1271152).
  • CVE-2026-59947: unsanitized URL credential handling in debug output within Composer can allow sensitive token disclosure (bsc#1271130).
  • CVE-2026-59948: missing package name validation during dependency resolution in Composer can allow path traversal (bsc#1271123).
References

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
php-composer2

Package

Name
php-composer2
Purl
pkg:rpm/suse/php-composer2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.2.30-150400.3.24.1

Ecosystem specific

{
    "binaries": [
        {
            "php-composer2": "2.2.30-150400.3.24.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4589-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
php-composer2

Package

Name
php-composer2
Purl
pkg:rpm/suse/php-composer2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.2.30-150400.3.24.1

Ecosystem specific

{
    "binaries": [
        {
            "php-composer2": "2.2.30-150400.3.24.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4589-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
php-composer2

Package

Name
php-composer2
Purl
pkg:rpm/suse/php-composer2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.2.30-150400.3.24.1

Ecosystem specific

{
    "binaries": [
        {
            "php-composer2": "2.2.30-150400.3.24.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4589-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
php-composer2

Package

Name
php-composer2
Purl
pkg:rpm/suse/php-composer2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.2.30-150400.3.24.1

Ecosystem specific

{
    "binaries": [
        {
            "php-composer2": "2.2.30-150400.3.24.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4589-1.json"
SUSE:Linux Enterprise Server 15 SP4-LTSS
php-composer2

Package

Name
php-composer2
Purl
pkg:rpm/suse/php-composer2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.2.30-150400.3.24.1

Ecosystem specific

{
    "binaries": [
        {
            "php-composer2": "2.2.30-150400.3.24.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4589-1.json"
SUSE:Linux Enterprise Server 15 SP5-LTSS
php-composer2

Package

Name
php-composer2
Purl
pkg:rpm/suse/php-composer2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.2.30-150400.3.24.1

Ecosystem specific

{
    "binaries": [
        {
            "php-composer2": "2.2.30-150400.3.24.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4589-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
php-composer2

Package

Name
php-composer2
Purl
pkg:rpm/suse/php-composer2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.2.30-150400.3.24.1

Ecosystem specific

{
    "binaries": [
        {
            "php-composer2": "2.2.30-150400.3.24.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4589-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
php-composer2

Package

Name
php-composer2
Purl
pkg:rpm/suse/php-composer2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.2.30-150400.3.24.1

Ecosystem specific

{
    "binaries": [
        {
            "php-composer2": "2.2.30-150400.3.24.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4589-1.json"