CVE-2026-59944

CVE-2026-59944 published: Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3, a malicious or compromised dependency can bypass the earlier CVE-2026-59946 binary-path hardening because Composer validates literal parent-directory s...

View full NVD advisory → ← Back to CVE watch