CVE-2026-45793Patch

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\IO\BaseIO::loadConfiguration() validates GitHub OAuth tokens with the regex ^[.A-Za-z0-9_]+$ and interpolates rejected tokens into an UnexpectedValueException; GitHub Actions GITHUB_TOKEN values using the ghs_<id>_<base64url-JWT> format can contain -, fail validation, and be disclosed to stderr or CI logs. This issue is fixed in versions 1.10.28, 2.2.28, and 2.9.8.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 8 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 6 mentions (2026-05-14); latest day: 1
  • 8 total mentions across 3 days

Deep dive

Activity timeline8 mentions / 3d
02356Mentions · 2026-05-13: 1Mentions · 2026-05-14: 6Mentions · 2026-05-26: 1Patch / Workaround · 2026-05-13: 1Patch / Workaround · 2026-05-14: 6Patch / Workaround · 2026-05-26: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-14: 6Technical Details · 2026-05-26: 105-1305-1405-26
Signal classification2 categories
Patch
675.0%
Disclosure
225.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-131
Disclosure1
2026-05-146
Disclosure1Patch5
2026-05-261
Patch1
Full discourse8 posts
  • yousukezan@yousukezan
    Patch

    PHP依存管理ツールComposerで、GitHub認証トークンがCI/CDログへ平文漏洩する重大欠陥が判明した。多数のリポジトリが認証情報窃取の危険に晒されている。 Composer共同開発者のNils Adermannは、CVE-2026-45793(CVSS 7.5)として追跡される脆弱性について緊急警告を発表した。問題はGitHubが導入した新形式のGITHUB_TOKENおよびGitHub Appインストールトークンにハイフン(-)が含まれるようになったことに起因する。 Composer側では2021年から使われていた検証ロジックがこの文字を許可しておらず、新形式トークンを「無効な文字を含む」と判定。その際、エラーメッセージ内へ完全なトークン文字列をそのままstderrへ出力していた。 CI/CD環境ではstderrがジョブログとして保存されることが多く、結果としてGitHub認証トークンが平文で記録される状態となっていた。さらにGitHub Actionsのシークレットマスキングは、改行や文字列分割が発生すると正確に伏字化できず、漏洩防止に失敗する場合がある。 影響範囲は広く、GitHub Appトークンを設定した状態でComposerコマンドを実行するワークフローが対象となる。GitHubホスト型ランナーでは漏洩トークンは最大6時間、自前運用のセルフホスト型では最大24時間有効となる可能性がある。 Composerチームは修正版2.9.8およびLTS版2.2.28を公開済みで、例外メッセージからトークン表示を削除し、新形式を受け入れるよう正規表現を修正した。利用者には即時アップデート、CI/CDログ監査、漏洩トークンの失効とローテーションが推奨されている。 https://securityonline.info/composer-github-token-leak-vulnerability-cve-2026-45793/

    Post summary

    Composer CVE‑2026‑45793 causes GitHub token leakage; official patches 2.9.8/2.2.28 are available and users are advised to update, audit CI/CD logs and rotate tokens.

    09592029232.0K
    14.5K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Composer CVE-2026-45793 leaks GitHub tokens into CI/CD logs due to a validation error. Update to version 2.9.8 now and audit your GitHub Action logs. #PHP #Composer #GitHub #CyberSecurity #InfoSec #CICD #DevOps #VulnerabilityAlert #CVE #WebDev #TechNews https://securityonline.info/composer-github-token-leak-vulnerability-cve-2026-45793/ https://t.co/l6GdUdCGa6

    Post summary

    The tweet alerts on Composer CVE‑2026‑45793, which leaks GitHub tokens in CI/CD logs, and urges users to upgrade to v2.9.8 and audit their GitHub Action logs to mitigate the vulnerability.

    0701521.2K
    12.5K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    【巻き添え】ComposerにログへのGitHubトークン漏洩の脆弱性。CVE-2026-45793は検証ロジックがGitHub側のトークン文字列が-を含むようになった仕様変更に追従できておらず、検証不適合でstderrにトークン入りのエラーログが吐かれてしまうもの。修正あり。 https://securityonline.info/composer-github-token-leak-vulnerability-cve-2026-45793/

    Post summary

    CVE-2026-45793 causes Composer to leak GitHub tokens to logs due to verification logic failure; a fix is available.

    040511.2K
    7.6K followersView on X
  • Tamas Erdelyi@terdelyi
    Patch

    🚨 Update Composer to 2.9.8 / 2.2.28 (or 1.10.28) CVE-2026-45793 leaks your GITHUB_TOKEN into public Actions logs when using 𝚜𝚑𝚒𝚟𝚊𝚖𝚖𝚊𝚝𝚑𝚞𝚛/𝚜𝚎𝚝𝚞𝚙-𝚙𝚑𝚙 with 𝚌𝚘𝚖𝚙𝚘𝚜𝚎𝚛 𝚒𝚗𝚜𝚝𝚊𝚕𝚕: https://blog.packagist.com/composer-2-9-8-and-2-2-28-fix-github-actions-token-disclosure-in-error-messages/

    Post summary

    The post announces a vulnerability that exposes GitHub tokens in logs and recommends upgrading Composer to patched versions to mitigate the risk.

    02120538
    233 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 High - Composer GitHub Actions Token Disclosure (CVE-2026-45793) Composer may expose GitHub Actions GITHUB_TOKEN values in CI logs when processing newer GitHub token formats containing hyphens (-). The issue occurs during token validation failures, causing the full token to be written to stderr and potentially leaked through workflow logs. The issue primarily affects GitHub Actions environments using Composer-integrated workflows and auto-configured OAuth tokens. 👉 Affected: Composer >= 2.3.0 < 2.9.8 | >= 2.0.0 < 2.2.28 | >= 1.0 < 1.10.28 👉 Fix: Upgrade to 2.9.8 / 2.2.28 / 1.10.28 and review CI logs for potential token exposure

    Post summary

    The text discloses a high severity Composer token leakage vulnerability, provides specific affected versions and an upgrade remedy, but does not mention PoCs, exploits, or active attacks.

    00020123
    255 followersView on X
  • AI Heartland@peaks2314
    Disclosure

    🚨 GitHub ActionsのCIログに、管理者権限トークンが平文で出力されていた。 Composer CVE-2026-45793(CVSS 7.5)。PHPプロジェクトをGitHub ActionsでCI回している人、ほぼ全員に関係します。 ⚠️何が起きた GitHubが4月にトークン形式を変更(ハイフン入りに) → Composer側の検証正規表現がコケる → 例外メッセージにトークン全文を載せてCIログへstderr出力。GitHub Actionsの自動マスキングをすり抜けて、生のトークンがログに見える状態に。 特にヤバいのはパブリックリポ。ログは誰でも閲覧可能で、漏れたトークンを拾えばリポジトリへの書き込みやシークレット抜き取りが可能。 GitHubは一旦ロールアウトをロールバック済みですが、過去に出力されたログ自体は消えていません。 ✅対策は1行 composer self-update 2.9.8 過去Actionsのfailedログも "ghs_" でgrep して要点検を。

    Post summary

    The post announces the CVE-2026-45793 vulnerability affecting Composer on GitHub Actions, explaining how admin tokens were exposed in CI logs, and recommends updating to Composer 2.9.8 as a mitigation.

    00020472
    3.4K followersView on X
  • IntegSec@integ_sec
    Patch

    CVE-2026-45793: GitHub Actions token disclosure in logs - What It Means for Your Business and How to Respond https://hubs.li/Q04hTpdH0

    Post summary

    The text is a guidance article outlining a GitHub Actions log token disclosure vulnerability and providing remediation steps, rather than offering an exploit or PoC.

    00000179
    31 followersView on X
  • SecureChap@SecureChap
    Patch

    UnexpectedValueException in Composer exposed raw GITHUB_TOKEN to GitHub Actions logs. CVE-2026-45793 (GHSA-f9f8-rm49-7jv2), published May 13, 2026. CVSS 7.5 (High), CWE-200 sensitive info exposure. Vulnerable ranges: Composer >= 2.3.0 < 2.9.8; >= 2.0.0 < 2.2.28; >= 1.0 < 1.10.28. Patches: 2.9.8, 2.2.28, 1.10.28. Trigger: BaseIO::loadConfiguration() applies regex ^[.A-Za-z0-9_]+$, excluding hyphens. Modern GitHub tokens follow ghs_<id>_<base64url-JWT> and contain hyphens, so they fail the check. Composer then throws UnexpectedValueException with the raw token in the message. Symfony Console dumps that to stderr. GitHub's secret masker matches exact substrings. Console wrapping or ANSI escape codes split the token across the output, so masking misses it and the plaintext lands in the public job log. Common precondition: shivammathur/setup-php and similar actions auto-register GITHUB_TOKEN into Composer's global auth.json. Scope is bound to the calling repo. Expires after 6h on hosted runners, 24h on self-hosted. Reported by damienwebdev and kesselb. The validation meant to protect the token became the path that disclosed it.

    Post summary

    CVE‑2026‑45793 exposes raw GitHub tokens in Composer logs due to a regex validation bug; patches are available for affected versions.

    00000119
    152 followersView on X

Explore more