Composer vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-67355Mediumguzzlehttp/guzzle: Guzzle: Host-only cookie scope is not preservedCVE-2026-67353Mediumguzzlehttp/guzzle: Guzzle: Unbounded response cookies risk denial of serviceCVE-2026-59883Mediumguzzlehttp/guzzle: Guzzle: Cookie Disclosure and Injection via IP-Address DomainsCVE-2026-59946Mediumcomposer/composer: Composer: Path traversal in package bin field lets dependencies chmod arbitrary host filesCVE-2026-59947Mediumcomposer/composer: Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)CVE-2026-67339Mediumguzzlehttp/guzzle: Guzzle: Proxy-Authorization headers can be sent to origin serversCVE-2026-59948Highcomposer/composer: Composer: Arbitrary file write outside vendor via malicious transitive package nameGHSA-CVPC-HCCG-WMW4Mediumverbb/formie: Formie: Missing authorization in administrative settings allows low-privileged CP users to modify plugin configurationCVE-2026-55579Criticalpheditor/pheditor: Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromiseCVE-2026-55578Highpheditor/pheditor: Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injectionCVE-2026-54540Highpheditor/pheditor: Pheditor has an authenticated terminal command whitelist bypassGHSA-XG43-5579-QW6VMediumadawolfa/isdoc: adawolfa/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF filesCVE-2026-62944Highmantisbt/mantisbt: MantisBT: Stored XSS in print_all_bug_page_word.phpCVE-2026-52883Mediummantisbt/mantisbt: MantisBT: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIsCVE-2026-52882Mediummantisbt/mantisbt: MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From UpdatersCVE-2026-52881Criticalmantisbt/mantisbt: MantisBT: Reflected XSS in admin/install.php via unescaped printf CVE-2026-52847Criticalmantisbt/mantisbt: MantisBT: Reflected XSS in admin/install.phpCVE-2026-54494Mediumphanan/koel: Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16)…CVE-2026-50552Mediumphanan/koel: Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bailCVE-2026-54491Highphanan/koel: Koel: Incomplete fix for CVE-2026-47260 — systemic SSRF in podcast & radio fetch pathsGHSA-8Q6Q-M837-FV64Mediumphanan/koel: Koel has SSRF through Authenticated Subsonic podcast feed URLsCVE-2026-54493Highphanan/koel: Koel: Authenticated Full-Read SSRF via Subsonic Internet Radio StationsCVE-2026-54492Mediumphanan/koel: Koel: Authenticated Blind SSRF via Subsonic Podcast Channel CreationCVE-2026-49280Mediummantisbt/mantisbt: MantisBT: REST API unauthorized Issue status changeCVE-2026-49273Highmantisbt/mantisbt: MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php

Stop the waste.
Protect your environment with Kodem.