Skip to content
Fedora 42 and 43 Address Composer Critical ANSI Injection Vulnerability

Fedora 42 and 43 Address Composer Critical ANSI Injection Vulnerability

First seen 14 Jan 2026, 09:52 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

Fedora has released updates for Composer version 2.9.3 to address a critical ANSI sequence injection vulnerability (CVE-2025-67746). The updates affect users managing PHP project dependencies and include fixes for the COMPOSER_NO_SECURITY_BLOCKING environment variable and issues with update commands. The security updates were made available on December 30, 2025.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track Fedora and CVE-2025-67746 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed