Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: setup-php Clear
ID Title
CVE-2026-46420 OS Command Injection in shivammathur/setup-php (CVE-2026-46420)
OS command injection in shivammathur/setup-php (CVE-2026-46420). Risk of unauthorized operations or information disclosure. Exploitable via ``composer.lock``. Mitigation: upgrade to `2.37.1` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →