Fedora 42 and 43 Address Composer Critical ANSI Injection Vulnerability

Fedora 42 and 43 Address Composer Critical ANSI Injection Vulnerability

First seen 14 Jan 2026, 09:52 UTC Linuxsecurity 33.7

Article Content

Browse articles
ThreatCluster

Fedora has released updates for Composer version 2.9.3 to address a critical ANSI sequence injection vulnerability (CVE-2025-67746). The updates affect users managing PHP project dependencies and include fixes for the COMPOSER_NO_SECURITY_BLOCKING environment variable and issues with update commands. The security updates were made available on December 30, 2025.