{
  "document": {
    "aggregate_severity": {
      "namespace": "https://www.suse.com/support/security/rating/",
      "text": "important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright 2024 SUSE LLC. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "summary",
        "text": "Security update for php-composer2",
        "title": "Title of the patch"
      },
      {
        "category": "description",
        "text": "This update for php-composer2 fixes the following issues:\n\n- CVE-2026-45793: GitHub OAuth tokens failing regex validation can cause credential disclosure (bsc#1271504).\n- CVE-2026-59944: path traversal and link following issue can make files world readable and executable (bsc#1279898).\n- CVE-2026-59946: package bin entries with path segments can cause unintended host file permission modifications\n  (bsc#1271152).\n- CVE-2026-59947: unsanitized URL credential handling in debug output within Composer can allow sensitive token\n  disclosure (bsc#1271130).\n- CVE-2026-59948: missing package name validation during dependency resolution in Composer can allow path traversal\n  (bsc#1271123).\n- CVE-2026-84361: arbitrary code execution via malicious Perforce source URL (bsc#1278257).\n\nChanges for php-composer2:\n\n- version update to 2.2.30:\n\n * Fixed command injection via malicious Perforce url (GHSA-rvx4-ffvw-m9q3)\n * Sanitize URL-embedded usernames/token in a few more places (#13045)\n * Fixed matching of gitlab URLs to avoid possible credential leak to the wrong domain (#13042)\n  \n- fix a regression on s390x due last change (bsc#1271729).\n\n- version update to 2.2.29:\n\n * Validate package names (GHSA-499r-g7pc-vmp9)\n * Validate package bin paths against path traversal (GHSA-gjfg-22fp-rrxx)\n * Sanitize URL-embedded usernames/token in verbose output (GHSA-g6xq-892h-64w3)\n * Only follow HTTP redirects from HTTP responses (#12948)\n * Prevent phar metadata unserialization on unsafe PHP versions (#12946)\n * Sanitize JSON parse errors in http responses to avoid leaking response body data (#12959)\n * Fixed GitHub token validation to be even more relaxed (#12856)\n  \n- version update to 2.2.28.\n",
        "title": "Description of the patch"
      },
      {
        "category": "details",
        "text": "SUSE-2026-4283,SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4283,SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4283,SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4283,SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4283,SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4283,SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4283,SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4283,SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4283",
        "title": "Patchnames"
      },
      {
        "category": "legal_disclaimer",
        "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).",
        "title": "Terms of use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://www.suse.com/support/security/contact/",
      "name": "SUSE Product Security Team",
      "namespace": "https://www.suse.com/"
    },
    "references": [
      {
        "category": "external",
        "summary": "SUSE ratings",
        "url": "https://www.suse.com/support/security/rating/"
      },
      {
        "category": "self",
        "summary": "URL of this CSAF notice",
        "url": "https://ftp.suse.com/pub/projects/security/csaf/suse-su-2026_4283-1.json"
      },
      {
        "category": "self",
        "summary": "URL for SUSE-SU-2026:4283-1",
        "url": "https://www.suse.com/support/update/announcement/2026/suse-su-20264283-1/"
      },
      {
        "category": "self",
        "summary": "E-Mail link for SUSE-SU-2026:4283-1",
        "url": "https://www.suse.com/support/update/announcement/2026/suse-su-20264283-1/"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1271123",
        "url": "https://bugzilla.suse.com/1271123"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1271130",
        "url": "https://bugzilla.suse.com/1271130"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1271152",
        "url": "https://bugzilla.suse.com/1271152"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1271504",
        "url": "https://bugzilla.suse.com/1271504"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1271729",
        "url": "https://bugzilla.suse.com/1271729"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1278257",
        "url": "https://bugzilla.suse.com/1278257"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1279898",
        "url": "https://bugzilla.suse.com/1279898"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-45793 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-45793/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-59944 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-59944/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-59946 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-59946/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-59947 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-59947/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-59948 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-59948/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-84361 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-84361/"
      }
    ],
    "title": "Security update for php-composer2",
    "tracking": {
      "current_release_date": "2026-09-23T08:31:54Z",
      "generator": {
        "date": "2026-09-22T08:35:35Z",
        "engine": {
          "name": "cve-database.git:bin/generate-csaf.pl",
          "version": "1"
        }
      },
      "id": "SUSE-SU-2026:4283-1",
      "initial_release_date": "2026-09-22T08:35:35Z",
      "revision_history": [
        {
          "date": "2026-09-22T08:35:35Z",
          "number": "1",
          "summary": "Current version"
        },
        {
          "date": "2026-09-23T08:31:54Z",
          "number": "2",
          "summary": "unknown changes"
        }
      ],
      "status": "final",
      "version": "2"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "php-composer2-0:2.2.30-150400.3.21.1.noarch",
                "product": {
                  "name": "php-composer2-0:2.2.30-150400.3.21.1.noarch",
                  "product_id": "php-composer2-0:2.2.30-150400.3.21.1.noarch",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:getcomposer:composer:2.2.30:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/php-composer2@2.2.30-150400.3.21.1?arch=noarch&upstream=php-composer2-0:2.2.30-150400.3.21.1.src.rpm"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS",
                "product": {
                  "name": "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS",
                  "product_id": "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sle_hpc-espos:15:sp4"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS",
                "product": {
                  "name": "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS",
                  "product_id": "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sle_hpc-ltss:15:sp4"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise High Performance Computing 15 SP4",
                "product": {
                  "name": "SUSE Linux Enterprise High Performance Computing 15 SP4",
                  "product_id": "SUSE Linux Enterprise High Performance Computing 15 SP4",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sle_hpc:15:sp4"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS",
                "product": {
                  "name": "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS",
                  "product_id": "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sle_hpc-espos:15:sp5"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS",
                "product": {
                  "name": "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS",
                  "product_id": "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sle_hpc-ltss:15:sp5"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise High Performance Computing 15 SP5",
                "product": {
                  "name": "SUSE Linux Enterprise High Performance Computing 15 SP5",
                  "product_id": "SUSE Linux Enterprise High Performance Computing 15 SP5",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sle_hpc:15:sp5"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise Server 15 SP4-LTSS",
                "product": {
                  "name": "SUSE Linux Enterprise Server 15 SP4-LTSS",
                  "product_id": "SUSE Linux Enterprise Server 15 SP4-LTSS",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sles-ltss:15:sp4"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise Server 15 SP4",
                "product": {
                  "name": "SUSE Linux Enterprise Server 15 SP4",
                  "product_id": "SUSE Linux Enterprise Server 15 SP4",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sles:15:sp4"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise Server for SAP Applications 15 SP4",
                "product": {
                  "name": "SUSE Linux Enterprise Server for SAP Applications 15 SP4",
                  "product_id": "SUSE Linux Enterprise Server for SAP Applications 15 SP4",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sles_sap:15:sp4"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "Open Enterprise Server 23.4",
                "product": {
                  "name": "Open Enterprise Server 23.4",
                  "product_id": "Open Enterprise Server 23.4",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:novell,inc:OES:23.4"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "Open Enterprise Server 24.4",
                "product": {
                  "name": "Open Enterprise Server 24.4",
                  "product_id": "Open Enterprise Server 24.4",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:novell,inc:OES:24.4"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise Server 15 SP5-LTSS",
                "product": {
                  "name": "SUSE Linux Enterprise Server 15 SP5-LTSS",
                  "product_id": "SUSE Linux Enterprise Server 15 SP5-LTSS",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sles-ltss:15:sp5"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise Server 15 SP5",
                "product": {
                  "name": "SUSE Linux Enterprise Server 15 SP5",
                  "product_id": "SUSE Linux Enterprise Server 15 SP5",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sles:15:sp5"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise Server for SAP Applications 15 SP5",
                "product": {
                  "name": "SUSE Linux Enterprise Server for SAP Applications 15 SP5",
                  "product_id": "SUSE Linux Enterprise Server for SAP Applications 15 SP5",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sles_sap:15:sp5"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "SUSE Linux Enterprise"
          }
        ],
        "category": "vendor",
        "name": "SUSE"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "php-composer2-0:2.2.30-150400.3.21.1.noarch as component of SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS",
          "product_id": "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch"
        },
        "product_reference": "php-composer2-0:2.2.30-150400.3.21.1.noarch",
        "relates_to_product_reference": "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "php-composer2-0:2.2.30-150400.3.21.1.noarch as component of SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS",
          "product_id": "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch"
        },
        "product_reference": "php-composer2-0:2.2.30-150400.3.21.1.noarch",
        "relates_to_product_reference": "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "php-composer2-0:2.2.30-150400.3.21.1.noarch as component of SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS",
          "product_id": "SUSE Linux Enterprise High Performance Computing 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch"
        },
        "product_reference": "php-composer2-0:2.2.30-150400.3.21.1.noarch",
        "relates_to_product_reference": "SUSE Linux Enterprise High Performance Computing 15 SP4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "php-composer2-0:2.2.30-150400.3.21.1.noarch as component of SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS",
          "product_id": "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch"
        },
        "product_reference": "php-composer2-0:2.2.30-150400.3.21.1.noarch",
        "relates_to_product_reference": "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "php-composer2-0:2.2.30-150400.3.21.1.noarch as component of SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS",
          "product_id": "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch"
        },
        "product_reference": "php-composer2-0:2.2.30-150400.3.21.1.noarch",
        "relates_to_product_reference": "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "php-composer2-0:2.2.30-150400.3.21.1.noarch as component of SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS",
          "product_id": "SUSE Linux Enterprise High Performance Computing 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch"
        },
        "product_reference": "php-composer2-0:2.2.30-150400.3.21.1.noarch",
        "relates_to_product_reference": "SUSE Linux Enterprise High Performance Computing 15 SP5"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "php-composer2-0:2.2.30-150400.3.21.1.noarch as component of SUSE Linux Enterprise Server 15 SP4-LTSS",
          "product_id": "SUSE Linux Enterprise Server 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch"
        },
        "product_reference": "php-composer2-0:2.2.30-150400.3.21.1.noarch",
        "relates_to_product_reference": "SUSE Linux Enterprise Server 15 SP4-LTSS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "php-composer2-0:2.2.30-150400.3.21.1.noarch as component of SUSE Linux Enterprise Server 15 SP4-LTSS",
          "product_id": "SUSE Linux Enterprise Server 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch"
        },
        "product_reference": "php-composer2-0:2.2.30-150400.3.21.1.noarch",
        "relates_to_product_reference": "SUSE Linux Enterprise Server 15 SP4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "php-composer2-0:2.2.30-150400.3.21.1.noarch as component of SUSE Linux Enterprise Server 15 SP4-LTSS",
          "product_id": "SUSE Linux Enterprise Server for SAP Applications 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch"
        },
        "product_reference": "php-composer2-0:2.2.30-150400.3.21.1.noarch",
        "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 15 SP4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "php-composer2-0:2.2.30-150400.3.21.1.noarch as component of SUSE Linux Enterprise Server 15 SP4-LTSS",
          "product_id": "Open Enterprise Server 23.4:php-composer2-0:2.2.30-150400.3.21.1.noarch"
        },
        "product_reference": "php-composer2-0:2.2.30-150400.3.21.1.noarch",
        "relates_to_product_reference": "Open Enterprise Server 23.4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "php-composer2-0:2.2.30-150400.3.21.1.noarch as component of SUSE Linux Enterprise Server 15 SP4-LTSS",
          "product_id": "Open Enterprise Server 24.4:php-composer2-0:2.2.30-150400.3.21.1.noarch"
        },
        "product_reference": "php-composer2-0:2.2.30-150400.3.21.1.noarch",
        "relates_to_product_reference": "Open Enterprise Server 24.4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "php-composer2-0:2.2.30-150400.3.21.1.noarch as component of SUSE Linux Enterprise Server 15 SP5-LTSS",
          "product_id": "SUSE Linux Enterprise Server 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch"
        },
        "product_reference": "php-composer2-0:2.2.30-150400.3.21.1.noarch",
        "relates_to_product_reference": "SUSE Linux Enterprise Server 15 SP5-LTSS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "php-composer2-0:2.2.30-150400.3.21.1.noarch as component of SUSE Linux Enterprise Server 15 SP5-LTSS",
          "product_id": "SUSE Linux Enterprise Server 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch"
        },
        "product_reference": "php-composer2-0:2.2.30-150400.3.21.1.noarch",
        "relates_to_product_reference": "SUSE Linux Enterprise Server 15 SP5"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "php-composer2-0:2.2.30-150400.3.21.1.noarch as component of SUSE Linux Enterprise Server 15 SP5-LTSS",
          "product_id": "SUSE Linux Enterprise Server for SAP Applications 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch"
        },
        "product_reference": "php-composer2-0:2.2.30-150400.3.21.1.noarch",
        "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 15 SP5"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-45793",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-45793"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\\IO\\BaseIO::loadConfiguration() validates GitHub OAuth tokens with the regex ^[.A-Za-z0-9_]+$ and interpolates rejected tokens into an UnexpectedValueException; GitHub Actions GITHUB_TOKEN values using the ghs_<id>_<base64url-JWT> format can contain -, fail validation, and be disclosed to stderr or CI logs. This issue is fixed in versions 1.10.28, 2.2.28, and 2.9.8.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "Open Enterprise Server 23.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "Open Enterprise Server 24.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server for SAP Applications 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server for SAP Applications 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-45793",
          "url": "https://www.suse.com/security/cve/CVE-2026-45793"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1271504 for CVE-2026-45793",
          "url": "https://bugzilla.suse.com/1271504"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "Open Enterprise Server 23.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "Open Enterprise Server 24.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server for SAP Applications 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server for SAP Applications 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "Open Enterprise Server 23.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "Open Enterprise Server 24.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server for SAP Applications 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server for SAP Applications 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:35:35Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-45793"
    },
    {
      "cve": "CVE-2026-59944",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-59944"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3, a malicious or compromised dependency can bypass the earlier CVE-2026-59946 binary-path hardening because Composer validates literal parent-directory segments only during dependency resolution, while the symlink and installed-metadata paths described by the advisory skip that validation. A package can ship an in-package binary symlink that resolves outside its installation directory, or attacker-influenced vendor/composer/installed.json metadata can provide an escaping binary path during a reinstall or regeneration of missing vendor/bin entries. The installed-metadata path is reachable only when the vendor directory was not populated by the same validated install run, such as when it is restored from an untrusted cache, copied from an earlier build stage, carried over from an older Composer run, or writable by a lower-trust build step. Composer can follow the path, change the external target's permissions to make it world-readable and executable, and create a runnable vendor/bin proxy to that external file. The issue does not directly read or transmit data and does not by itself provide remote code execution. This issue is fixed in versions 2.2.30 and 2.10.3.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "Open Enterprise Server 23.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "Open Enterprise Server 24.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server for SAP Applications 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server for SAP Applications 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-59944",
          "url": "https://www.suse.com/security/cve/CVE-2026-59944"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1279898 for CVE-2026-59944",
          "url": "https://bugzilla.suse.com/1279898"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "Open Enterprise Server 23.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "Open Enterprise Server 24.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server for SAP Applications 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server for SAP Applications 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "Open Enterprise Server 23.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "Open Enterprise Server 24.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server for SAP Applications 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server for SAP Applications 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:35:35Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-59944"
    },
    {
      "cve": "CVE-2026-59946",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-59946"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containing .. path segments can resolve outside the package install directory and cause Composer's binary installation flow to chmod an existing host file to a world-readable and world-executable mode during composer install, update, or require. This issue is fixed in versions 2.2.29 and 2.10.2.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "Open Enterprise Server 23.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "Open Enterprise Server 24.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server for SAP Applications 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server for SAP Applications 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-59946",
          "url": "https://www.suse.com/security/cve/CVE-2026-59946"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1271151 for CVE-2026-59946",
          "url": "https://bugzilla.suse.com/1271151"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "Open Enterprise Server 23.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "Open Enterprise Server 24.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server for SAP Applications 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server for SAP Applications 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "Open Enterprise Server 23.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "Open Enterprise Server 24.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server for SAP Applications 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server for SAP Applications 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:35:35Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-59946"
    },
    {
      "cve": "CVE-2026-59947",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-59947"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, when Composer is run with -vvv debug verbosity, it could print a credential embedded in the username slot of a repository or package URL, such as a GitHub Personal Access Token in https://TOKEN@host/, to debug output because AuthHelper, Url::sanitize, and ProcessExecutor did not sanitize username-only URL credentials. This issue is fixed in versions 2.2.29 and 2.10.2.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "Open Enterprise Server 23.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "Open Enterprise Server 24.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server for SAP Applications 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server for SAP Applications 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-59947",
          "url": "https://www.suse.com/security/cve/CVE-2026-59947"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1271129 for CVE-2026-59947",
          "url": "https://bugzilla.suse.com/1271129"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "Open Enterprise Server 23.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "Open Enterprise Server 24.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server for SAP Applications 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server for SAP Applications 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.7,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "Open Enterprise Server 23.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "Open Enterprise Server 24.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server for SAP Applications 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server for SAP Applications 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:35:35Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-59947"
    },
    {
      "cve": "CVE-2026-59948",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-59948"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an untrusted repository other than Packagist.org or Private Packagist can cause Composer to write attacker-controlled files outside the vendor directory and outside the project during install or update by using an invalid package name that is not correctly validated before dependency-resolution results are written or installed. This issue is fixed in versions 2.2.29 and 2.10.2.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "Open Enterprise Server 23.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "Open Enterprise Server 24.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server for SAP Applications 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server for SAP Applications 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-59948",
          "url": "https://www.suse.com/security/cve/CVE-2026-59948"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1271122 for CVE-2026-59948",
          "url": "https://bugzilla.suse.com/1271122"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "Open Enterprise Server 23.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "Open Enterprise Server 24.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server for SAP Applications 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server for SAP Applications 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "Open Enterprise Server 23.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "Open Enterprise Server 24.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server for SAP Applications 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server for SAP Applications 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:35:35Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-59948"
    },
    {
      "cve": "CVE-2026-84361",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-84361"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package from a custom Composer repository or an untrusted composer.lock file could set source.type to perforce and source.url to an rsh: or jsh: P4PORT value. When the Perforce p4 client was installed and Composer installed the package from source through composer install or composer update, including --prefer-source, Composer\\Util\\Perforce passed the address to p4 without validation, causing p4 to run a local command with the privileges of the user or CI account. Packagist.org does not permit Perforce source metadata. This issue is fixed in versions 2.2.30 and 2.10.3.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "Open Enterprise Server 23.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "Open Enterprise Server 24.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise High Performance Computing 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server for SAP Applications 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
          "SUSE Linux Enterprise Server for SAP Applications 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-84361",
          "url": "https://www.suse.com/security/cve/CVE-2026-84361"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1278257 for CVE-2026-84361",
          "url": "https://bugzilla.suse.com/1278257"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1280019 for CVE-2026-84361",
          "url": "https://bugzilla.suse.com/1280019"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "Open Enterprise Server 23.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "Open Enterprise Server 24.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server for SAP Applications 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server for SAP Applications 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "Open Enterprise Server 23.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "Open Enterprise Server 24.4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise High Performance Computing 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP4-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP5-LTSS:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server for SAP Applications 15 SP4:php-composer2-0:2.2.30-150400.3.21.1.noarch",
            "SUSE Linux Enterprise Server for SAP Applications 15 SP5:php-composer2-0:2.2.30-150400.3.21.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:35:35Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-84361"
    }
  ]
}