Amazon Linux 2023 Security Advisory: ALAS2023-2026-1941
Advisory Released Date: 2026-07-20
Advisory Updated Date: 2026-07-20
FAQs regarding Amazon Linux ALAS/CVE Severity
Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containing .. path segments can resolve outside the package install directory and cause Composer's binary installation flow to chmod an existing host file to a world-readable and world-executable mode during composer install, update, or require. This issue is fixed in versions 2.2.29 and 2.10.2. (CVE-2026-59946)
Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, when Composer is run with -vvv debug verbosity, it could print a credential embedded in the username slot of a repository or package URL, such as a GitHub Personal Access Token in https://TOKEN@host/, to debug output because AuthHelper, Url::sanitize, and ProcessExecutor did not sanitize username-only URL credentials. This issue is fixed in versions 2.2.29 and 2.10.2. (CVE-2026-59947)
Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an untrusted repository other than Packagist.org or Private Packagist can cause Composer to write attacker-controlled files outside the vendor directory and outside the project during install or update by using an invalid package name that is not correctly validated before dependency-resolution results are written or installed. This issue is fixed in versions 2.2.29 and 2.10.2. (CVE-2026-59948)
Affected Packages:
composer
Issue Correction:
Run dnf update composer --releasever 2023.12.20260720 or dnf update --advisory ALAS2023-2026-1941 --releasever 2023.12.20260720 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
noarch:
composer-2.10.2-1.amzn2023.0.1.noarch
src:
composer-2.10.2-1.amzn2023.0.1.src