Fedora Security Advisories: Composer Token Fix and PIE Dependency Updates

Fedora Security Advisories: Composer Token Fix and PIE Dependency Updates

First seen 23 May 2026, 23:33 UTC Linuxsecurity 80% similarity 60.6

Article Content

Browse articles
ThreatCluster

On May 13, 2026, Fedora released security updates for Composer 2.9.8, addressing a critical GitHub token validation issue (GHSA-f9f8-rm49-7jv2) that could lead to unauthorized disclosure of tokens. This vulnerability affects both Fedora 43 and Fedora 44 systems. Additionally, an update for the PIE (PHP Installer for Extensions) was released to version 1.4.4, which includes various dependency fixes and improvements. The updates can be installed using the 'dnf' package manager. Users are advised to apply these updates promptly to mitigate potential risks associated with the vulnerabilities. The updates were confirmed by Remi Collet, the maintainer, and are available through the respective Fedora advisory notifications.

Key Points: • Fedora released Composer 2.9.8 to fix a critical GitHub token validation issue. • The PIE update to version 1.4.4 includes important dependency fixes. • Users are urged to apply updates via 'dnf' to protect against potential vulnerabilities.

ThreatCluster AI

Timeline

2026-05-13
Composer 2.9.8 released
Fedora released Composer 2.9.8 to fix a GitHub token validation vulnerability affecting versions 43 and 44.
Linuxsecurity
2026-05-13
PIE updated to version 1.4.4
Fedora updated the PIE package to version 1.4.4, addressing dependency issues and improving functionality.
Linuxsecurity
2026-05-23
Security advisories published
Fedora published security advisories for both Composer and PIE updates, urging users to apply them immediately.
Linuxsecurity

Community

Browse all →