{"api_version":"v1","generated_at":"2026-10-07T22:50:00+00:00","product":{"cve_count":16,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-composer-composer-a1797e957f82","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/composer","name":"composer","next_cursor":null,"observations":[{"affected":"composer: >= 1.0.0, < 2.2.30, >= 2.3.0, < 2.10.3","affected_versions_present":true,"cve_id":"CVE-2026-59944","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59944","fixed":"For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/","last_modified":"2026-09-16T17:29:39.824Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-59944","primary_source":"","published":"2026-09-16T16:09:43.258Z"},{"affected":">= 1.0, < 2.2.30; >= 2.3.0, < 2.10.3","affected_versions_present":true,"cve_id":"CVE-2026-84361","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-84361","fixed":"For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/","last_modified":"2026-09-03T03:56:08.149Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-84361","primary_source":"","published":"2026-09-01T20:06:48.375Z"},{"affected":">= 1.0, < 1.10.28; >= 2.0.0, < 2.2.28; >= 2.3.0, < 2.9.8","affected_versions_present":true,"cve_id":"CVE-2026-45793","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45793","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-15T18:11:10.355Z","patch_url":"https://www.suse.com/security/cve/CVE-2026-45793","primary_source":"","published":"2026-07-15T16:22:19.418Z"},{"affected":">= 1.0, < 2.2.29; >= 2.3.0, < 2.10.2","affected_versions_present":true,"cve_id":"CVE-2026-59947","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59947","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-09T14:01:42.612Z","patch_url":"https://www.suse.com/security/cve/CVE-2026-59947","primary_source":"","published":"2026-07-08T19:33:56.009Z"},{"affected":">= 1.0, < 2.2.29; >= 2.3.0, < 2.10.2","affected_versions_present":true,"cve_id":"CVE-2026-59948","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59948","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-09T14:32:07.719Z","patch_url":"https://www.suse.com/security/cve/CVE-2026-59948","primary_source":"","published":"2026-07-08T19:33:48.414Z"},{"affected":">= 1.0, < 2.2.29; >= 2.3.0, < 2.10.2","affected_versions_present":true,"cve_id":"CVE-2026-59946","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59946","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-09T14:41:23.436Z","patch_url":"https://www.suse.com/security/cve/CVE-2026-59946","primary_source":"","published":"2026-07-08T19:32:38.089Z"},{"affected":">= 2.3.0, < 2.9.6; >= 1.0.0, < 2.2.27","affected_versions_present":true,"cve_id":"CVE-2026-40261","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40261","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-15T01:01:10.106Z","patch_url":"","primary_source":"","published":"2026-04-15T20:56:32.182Z"},{"affected":">= 2.3, < 2.9.6; >= 1.0, < 2.2.27","affected_versions_present":true,"cve_id":"CVE-2026-40176","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40176","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-15T01:01:19.144Z","patch_url":"","primary_source":"","published":"2026-04-15T20:47:39.839Z"},{"affected":">= 2.0, < 2.2.26; >= 2.3, < 2.9.3","affected_versions_present":true,"cve_id":"CVE-2025-67746","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-67746","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-12-30T17:30:04.562Z","patch_url":"https://github.com/composer/composer/commit/1d40a95c9d39a6b7f80d404ab30336c586da9917","primary_source":"","published":"2025-12-30T16:11:04.776Z"},{"affected":">= 2.0, < 2.2.24; >= 2.3, < 2.7.7","affected_versions_present":true,"cve_id":"CVE-2024-35242","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-35242","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-02-13T17:52:34.786Z","patch_url":"","primary_source":"","published":"2024-06-10T21:23:44.040Z"},{"affected":">= 2.0, < 2.2.24; >= 2.3, < 2.7.7","affected_versions_present":true,"cve_id":"CVE-2024-35241","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-35241","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-21T15:20:35.089Z","patch_url":"","primary_source":"","published":"2024-06-10T21:19:47.123Z"},{"affected":">= 2.0, < 2.2.23; >= 2.3, < 2.7","affected_versions_present":true,"cve_id":"CVE-2024-24821","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-24821","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-06-17T21:29:29.230Z","patch_url":"https://github.com/composer/composer/commit/64e4eb356b159a30c766cd1ea83450a38dc23bf5","primary_source":"","published":"2024-02-08T23:54:04.058Z"},{"affected":"2.6.4, 2.2.21, 1.10.27; >= 2.0, < 2.2.22; < 1.10.27","affected_versions_present":true,"cve_id":"CVE-2023-43655","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-43655","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-06-18T13:59:58.568Z","patch_url":"https://github.com/composer/composer/commit/4fce14795aba98e40b6c4f5047305aba17a6120d","primary_source":"","published":"2023-09-29T19:33:32.183Z"},{"affected":"< 1.10.26; >= 2.0.0, < 2.2.12; >= 2.3, < 2.3.6","affected_versions_present":true,"cve_id":"CVE-2022-24828","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-24828","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T18:40:09.513Z","patch_url":"https://github.com/composer/composer/commit/2c40c53637c5c7e43fff7c09d3d324d632734709","primary_source":"","published":"2022-04-13T21:00:22.000Z"},{"affected":"< 1.10.23; >= 2.0, < 2.1.9","affected_versions_present":true,"cve_id":"CVE-2021-41116","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-41116","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T02:59:31.440Z","patch_url":"https://github.com/composer/composer/commit/ca5e2f8d505fd3bfac6f7c85b82f2740becbc0aa","primary_source":"","published":"2021-10-05T17:40:10.000Z"},{"affected":"< 1.10.22; >=2.0,<2.0.13","affected_versions_present":true,"cve_id":"CVE-2021-29472","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-29472","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-03T22:11:05.384Z","patch_url":"","primary_source":"","published":"2021-04-27T20:30:15.000Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"composer"}}
