Linuxsecurity
Fedora 42 and 43 Address Composer Critical ANSI Injection Vulnerability
First seen 14 Jan 2026, 09:52 UTC
•
•33.7
Export
Article Content
Browse articles
Fedora has released updates for Composer version 2.9.3 to address a critical ANSI sequence injection vulnerability (CVE-2025-67746). The updates affect users managing PHP project dependencies and include fixes for the COMPOSER_NO_SECURITY_BLOCKING environment variable and issues with update commands. The security updates were made available on December 30, 2025.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Fedora Skopeo Security Fix for CVE-2025-58189 and CVE-2025-61725
Critical CVE-2026-11332 Affects Fedora Ansible-Core Versions
Critical Buffer Overflow Vulnerability in pyOpenSSL Requires Immediate Action
Fedora Coturn Security Bypass Vulnerabilities Addressed in Recent Updates
Multiple Fedora Rust Packages Vulnerable to libgit2 Security Flaws
Oracle Linux Kernel ptrace Vulnerability CVE-2026-46333 Disclosed