VulnSea

composer has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was July 2026 with 3. The median CVSS is 6.1 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-22 (3). Most affected products: composer/composer (4), composer (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.1
Publish → KEV
Last 90 days
5 prev 0

Products

  • composer/composer 4
  • composer 1
5
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

composer vulnerabilities

CVEs affecting composer, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-59944Medium· 6.1
6d ago

Composer is a dependency Manager for the PHP language

Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3, a malicious or compromised dependency can bypass the earlier CVE-2026-59946 binary-path hardening because Composer validates litera…

Sunlitcomposer · composerEPSS 0.45%via NVD
CVE-2026-84361HighPoC
3w ago

Composer is a dependency Manager for the PHP language

Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package from a custom Composer repository or an untrusted composer.lock file could set source.type to perforce and source.url…

Midnightcomposer · composer/composerEPSS 0.41%via NVD
CVE-2026-59947Medium· 4.7
2mo ago

Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)

Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)

Sunlitcomposer · composer/composerEPSS 0.14%via GHSA
CVE-2026-59946Medium· 6.1
2mo ago

Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files

Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files

Sunlitcomposer · composer/composerEPSS 0.17%via GHSA
CVE-2026-59948High· 7.0
2mo ago

Composer: Arbitrary file write outside vendor via malicious transitive package name

Composer: Arbitrary file write outside vendor via malicious transitive package name

Twilightcomposer · composer/composerEPSS 0.16%via GHSA
composer vulnerabilities (CVEs) · VulnSea