StackRadar

CVE-2026-59944

Medium

Advisory

Published 25 Sept 2026In the index since 26 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.003
23rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
14
of 17,988 indexed, latest versions
Container images
10
deployed by those charts
Fix available
2 of 2
affected packages

Composer: CVE-2026-59946 fix bypass via symlinked package bin path

Carried by container images the latest versions of 14 of 17,988 indexed charts deploy, on 10 images.

Affected packageAffected versionsFixed inImages
composer/composercomposer1.7.0, 1.10.24, 2.1.11, 2.1.14+2 more2.2.30, 2.10.37
composerbitnami2.8.10, 2.10.12.2.303
OSV records
BIT-composer-2026-59944GHSA-96h3-5x6v-m776

Charts affected

14 by stars
ChartLatestAffected imagesRadar Score
mauticone-acre-fundVerified publisher0.1.71 of 3See more

mautic one-acre-fund 0.1.7

1 of the 3 container images this version deploys carry CVE-2026-59944.

Container imageDigestPackageFixed in
mautic/mautic:v4-apache94ea4acf4049
composer/composer@2.2.12
2.2.30

Open the chart page →

3,576
repmanszpadel-chartsVerified publisher3.52.171 of 3See more

repman szpadel-charts 3.52.17

1 of the 3 container images this version deploys carry CVE-2026-59944.

Container imageDigestPackageFixed in
buddy/repman:1.4.0097c897f8b54
composer/composer@1.10.24
2.2.30

Open the chart page →

7,522
repmanrepman-helmchartVerified publisher1.0.121 of 3See more

repman repman-helmchart 1.0.12

1 of the 3 container images this version deploys carry CVE-2026-59944.

Container imageDigestPackageFixed in
buddy/repman:1.4.0097c897f8b54
composer/composer@1.10.24
2.2.30

Open the chart page →

4,334
satisfyanapsixVerified publisher1.1.31 of 1See more

satisfy anapsix 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-59944.

Container imageDigestPackageFixed in
anapsix/satisfydigest-pinnedfae78e3809e9
composer/composer@1.7.0
2.2.30

Open the chart page →

1,586
satisfycloudnativeapp1.0.01 of 1See more

satisfy cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-59944.

Container imageDigestPackageFixed in
anapsix/satisfydigest-pinnedfae78e3809e9
composer/composer@1.7.0
2.2.30

Open the chart page →

1,586
bookstackgeek-cookbookVerified publisher5.2.01 of 1See more

bookstack geek-cookbook 5.2.0

1 of the 1 container images this version deploys carry CVE-2026-59944.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/bookstack:version-v21.12f05447347ff1
composer/composer@2.1.14
2.2.30

Open the chart page →

1,339
mauticmautic-chartVerified publisher1.0.21 of 3See more

mautic mautic-chart 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-59944.

Container imageDigestPackageFixed in
mautic/mautic:7-apacheeb8cc73d97e1
composer/composer@2.10.0
2.10.3

Open the chart page →

9,584
moodlemoodle1.0.41 of 2See more

moodle moodle 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-59944.

Container imageDigestPackageFixed in
cloudtooling/moodle:5.2.43c3625e3a6b0
composer@2.10.1
2.2.30

Open the chart page →

4,344
matomopetbattle11.0.11 of 2See more

matomo petbattle 11.0.1

1 of the 2 container images this version deploys carry CVE-2026-59944.

Container imageDigestPackageFixed in
bitnamilegacy/matomo:5.3.2-debian-12-r13f02c000c54b1
composer@2.8.10
2.2.30

Open the chart page →

12,620
shopwarerobjuz2.0.01 of 6See more

shopware robjuz 2.0.0

1 of the 6 container images this version deploys carry CVE-2026-59944.

Container imageDigestPackageFixed in
shyim/shopware:6.4.6.0a951c0e6b836
composer/composer@2.1.11
2.2.30

Open the chart page →

3,416
bookstackschmitzis0.1.11 of 1See more

bookstack schmitzis 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59944.

Container imageDigestPackageFixed in
solidnerd/bookstack:21.12762ffd5c51d3
composer/composer@2.1.14
2.2.30

Open the chart page →

3,701
repmanteam-blueVerified publisher0.3.01 of 5See more

repman team-blue 0.3.0

1 of the 5 container images this version deploys carry CVE-2026-59944.

Container imageDigestPackageFixed in
buddy/repman:1.4.0097c897f8b54
composer/composer@1.10.24
2.2.30

Open the chart page →

4,138
wordpresswordpress-ng1.0.101 of 2See more

wordpress wordpress-ng 1.0.10

1 of the 2 container images this version deploys carry CVE-2026-59944.

Container imageDigestPackageFixed in
cloudtooling/wordpress:7.1.20b390e7e3425
composer@2.10.1
2.2.30

Open the chart page →

4,396
satisfyymrs1.0.21 of 1See more

satisfy ymrs 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-59944.

Container imageDigestPackageFixed in
anapsix/satisfydigest-pinnedfae78e3809e9
composer/composer@1.7.0
2.2.30

Open the chart page →

1,586

Container images carrying it

10 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
anapsix/satisfyfae78e3809e9
composer/composer@1.7.0
2.2.30
3
buddy/repman:1.4.0097c897f8b54
composer/composer@1.10.24
2.2.30
3
bitnamilegacy/matomo:5.3.2-debian-12-r13f02c000c54b1
composer@2.8.10
2.2.30
1
cloudtooling/moodle:5.2.43c3625e3a6b0
composer@2.10.1
2.2.30
1
cloudtooling/wordpress:7.1.20b390e7e3425
composer@2.10.1
2.2.30
1
mautic/mautic:v4-apache94ea4acf4049
composer/composer@2.2.12
2.2.30
1
mautic/mautic:7-apacheeb8cc73d97e1
composer/composer@2.10.0
2.10.3
1
shyim/shopware:6.4.6.0a951c0e6b836
composer/composer@2.1.11
2.2.30
1
solidnerd/bookstack:21.12762ffd5c51d3
composer/composer@2.1.14
2.2.30
1
ghcr.io/linuxserver/bookstack:version-v21.12f05447347ff1
composer/composer@2.1.14
2.2.30
1

syft 1.42.1 · advisories as of 4 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.